CVE-2023-50044

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 20, 2023
Updated: Dec 29, 2023
CWE ID 120

Summary

CVE-2023-50044 is a Critical vulnerability that affects Cesanta MJS version 2.20.0. The vulnerability allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information through a Buffer Overflow. This occurs when the input string includes the name of Built-in APIs, leading to an out-of-bounds read in the getprop_builtin_foreign function. The vulnerability has a base severity score of 9.8 according to NIST and poses a high risk to organizations as it can be exploited remotely over a network without requiring any privileges or user interaction. It has a high impact on confidentiality, integrity, and availability of affected systems. Remediating this vulnerability requires updating to a version of Cesanta MJS that is not affected by the issue (2.22.0 or later).

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-50044 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions