nodejs / nodejs/nodejs-dependency-vuln-assessments

Whether V8: CVE-2024-3159 and V8: CVE-2024-3156 have impact on the use of nodejs ?

Open
#184 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

dont-believe-affects-nodejs
Dominant language
Python
Stars
22
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Version
21.7.2

Platform
No response

Subsystem
No response

What steps will reproduce the bug?
No response

How often does it reproduce? Is there a required condition?
No response

What is the expected behavior? Why is that the expected behavior?
No response

What do you see instead?
Hi colleague,

In recent BDBA scan, there are two CVE:
CVE-2024-3159
CVE-2024-3156

detected in node.js.
According to the description of above, it was detected in V8 in Google Chrome. Here we would like to further confirm whether it is true positive in node.js or not.

Additional information
3159: Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
3156: Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Best regards,
Shaofeng

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked advisories for CVE-2024-3159 and CVE-2024-3156 alongside the reported Node.js version 21.7.2. Determine whether the V8 vulnerabilities apply to Node.js, then document the evidence and affected or unaffected versions in the issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
nodejs
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.