-
-
Notifications
You must be signed in to change notification settings - Fork 6
Open
Labels
dont-fall-in-threat-modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat model
Description
Hi colleague,
In recent BDBA scan, there is one CVE:
https://nvd.nist.gov/vuln/detail/CVE-2024-7535
detected in node.js.
According to the description of above, it was detected in V8 in Google Chrome. Here we would like to further confirm whether it is true positive in node.js or not.
Additional information
Inappropriate implementation in V8 in Google Chrome prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Best regards,
Peilin
Metadata
Metadata
Assignees
Labels
dont-fall-in-threat-modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat modelWhen a vulnerability might affect Node.js but do not fall in the Node.js threat model