CVE-2023-30363: Critical severity tencent vconsole vulnerability
Published Apr 26, 2023
·Updated
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Other sources
vConsole was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Affected Software
2 affected componentsFixes available
Tencent Vconsole=3.15.0
npm/vconsole<3.15.1
3.15.1
Event History
Apr 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-30363?
The severity of CVE-2023-30363 is critical with a CVSS score of 9.8.
2
What is the vulnerability description of CVE-2023-30363?
CVE-2023-30363 is a prototype pollution vulnerability found in vConsole v3.15.0 due to incorrect key and value resolution in setOptions in core.ts.
3
Which software versions are affected by CVE-2023-30363?
vConsole v3.15.0 is affected by CVE-2023-30363.
4
How can I fix CVE-2023-30363?
To fix CVE-2023-30363, update vConsole to a version higher than 3.15.0.
5
Where can I find more information about CVE-2023-30363?
More information about CVE-2023-30363 can be found on the NIST NVD, GitHub, and MITRE CWE websites.