First published: Tue Jun 13 2023(Updated: )
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
Credit: security@huntr.dev security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
npm/nuxt | >=3.4.0<3.4.3 | 3.4.3 |
nCipher | <3.5.3 | |
Nuxt.js | >=3.4.0<3.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3224 has been classified as a high severity vulnerability due to its potential for code injection.
To mitigate CVE-2023-3224, upgrade the Nuxt framework to version 3.5.3 or later.
CVE-2023-3224 affects Nuxt versions between 3.4.0 and 3.4.3.
CVE-2023-3224 is a code injection vulnerability present in the Nuxt dev server.
It is unsafe to use the Nuxt dev server prior to upgrading because the vulnerability allows for potential code injection.