CVE-2023-45811

CVSS V2 None CVSS V3 None
Description
Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer allowing crafted input to modify properties in the Object prototype. A fix has been released in `deobfuscator@2.4.4`. Users are advised to upgrade. Users unable to upgrade should launch node with the [--disable-proto=delete][disable-proto] or [--disable-proto=throw][disable-proto] flags
Overview
  • CVE ID
  • CVE-2023-45811
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-17T22:37:20.249Z
  • Last Modified Date
  • 2023-10-17T22:37:20.249Z
History
Created Old Value New Value Data Type Notes
2024-06-25 10:30:30 Added to TrackCVE