CVE-2018-8452
MEDIUM4.3EPSS 11.4%ChakraCore information disclosure vulnerability
發布日:2022/5/13修改日:2024/2/16
描述
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.
受影響套件(1)
- NuGet/Microsoft.ChakraCorefrom 0, < 1.11.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-8452
- PATCHhttps://github.com/chakra-core/ChakraCore
- WEBhttps://github.com/chakra-core/ChakraCore/commit/3f3544801cc01e9f54cab84b20602a3b5e29c3ef
- WEBhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8452
- WEBhttps://web.archive.org/web/20210124203129/http://www.securityfocus.com/bid/105252
- WEBhttps://web.archive.org/web/20221128100304/http://www.securitytracker.com/id/1041623