CVE-2023-31874

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published May 29, 2023
Updated: Jan 14, 2025
CWE ID 732

Summary

CVE-2023-31874 is a newly identified vulnerability in Yank Note (YN) 3.52.1. This issue permits the execution of arbitrary code when a specially crafted file is opened using the 'nodeRequire' function with 'child_process'. This vulnerability poses a significant risk, potentially allowing an attacker to run unauthorized code and gain unauthorized access to a system. Users are strongly encouraged to update their Yank Note application to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share