logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-28445

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-28445

Description:
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in the wild, as the only version affected is Deno 1.32.0. Deno Deploy users are not affected. The problem has been resolved by disabling resizable ArrayBuffers temporarily in Deno 1.32.1. Deno 1.32.2 will re-enable resizable ArrayBuffers with a proper fix. As a workaround, run with `--v8-flags=--no-harmony-rab-gsab` to disable resizable ArrayBuffers.
Last updated date:
03/31/2023

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
03/24/2023
Reference url to background

https://nvd.nist.gov/vuln/detail/CVE-2023-28445

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy