CVE-2020-14000: Critical severity scratch vm vulnerability
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain characters, resulting in remote code execution because the URL's content is treated as a script and is executed as a worker. The responsible code is getExtensionIdForOpcode in serialization/sb3.js. The use of is incompatible with a protection mechanism in older versions, in which URLs were split and consequently deserialization attacks were prevented.
NOTE: the scratch.mit.edu hosted service is not affected because of the lack of worker scripts.
Other sources
MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain characters, resulting in remote code execution because the URL's content is treated as a script and is executed as a worker. The responsible code is getExtensionIdForOpcode in serialization/sb3.js. The use of is incompatible with a protection mechanism in older versions, in which URLs were split and consequently deserialization attacks were prevented. NOTE: the scratch.mit.edu hosted service is not affected because of the lack of worker scripts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-14000?
The severity of CVE-2020-14000 is critical with a severity value of 9.8.
How can I fix CVE-2020-14000?
To fix CVE-2020-14000, update the affected software to version 0.2.0-prerelease.20200714185213 or later.
What is the affected software version for CVE-2020-14000?
The affected software version for CVE-2020-14000 is up to and including version 0.2.0-prerelease.20200714185213.
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-14000?
The Common Weakness Enumeration (CWE) ID for CVE-2020-14000 is 502.
Where can I find more information about CVE-2020-14000?
You can find more information about CVE-2020-14000 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-14000), [GitHub pull request #2476](https://github.com/LLK/scratch-vm/pull/2476), [GitHub commit 90b9da45f4084958535338d1c4d71a22d6136aab](https://github.com/LLK/scratch-vm/pull/2476/commits/90b9da45f4084958535338d1c4d71a22d6136aab).