CVE-2023-31922: High severity quickjs vulnerability
Published May 12, 2023
·Updated
QuickJS commit 2788d71 was discovered to contain a stack-overflow via the component jsproxyisArray at quickjs.c.
Affected Software
1 affected component
Quickjs Project Quickjs=2022-03-06
Event History
May 12, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-31922?
CVE-2023-31922 has a high-severity rating due to the potential for remote code execution via stack overflow.
2
How do I fix CVE-2023-31922?
To fix CVE-2023-31922, you should update to the latest version of QuickJS that includes the patch for the vulnerability.
3
What components are affected by CVE-2023-31922?
CVE-2023-31922 specifically affects versions of QuickJS prior to the fix implemented after commit 2788d71.
4
What is the nature of the vulnerability in CVE-2023-31922?
CVE-2023-31922 is a stack overflow vulnerability that occurs in the js_proxy_isArray component of QuickJS.
5
Is CVE-2023-31922 exploitable in production systems?
Yes, CVE-2023-31922 can be exploited in production systems if they are running the vulnerable version of QuickJS.