CVE-2024-23347: High severity Facebook Meta Spark Studio vulnerability
Published Jan 16, 2024
·Updated
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
Affected Software
1 affected component
Facebook Meta Spark Studio<176
Event History
Jan 16, 2024
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23347?
CVE-2024-23347 is considered a critical vulnerability due to its ability to execute arbitrary code.
2
How do I fix CVE-2024-23347?
To mitigate CVE-2024-23347, update Meta Spark Studio to version 176 or later.
3
What causes CVE-2024-23347?
CVE-2024-23347 is caused by the execution of scripts defined in the package.json file when opening a new project in versions prior to 176.
4
Who is affected by CVE-2024-23347?
Users of Meta Spark Studio versions prior to 176 are affected by CVE-2024-23347.
5
What types of systems are vulnerable to CVE-2024-23347?
CVE-2024-23347 can affect any system where Meta Spark Studio versions before 176 are installed.