CVE-2022-25863
🟠 Łataj w tym tygodniu
Deserializacja niezaufanych danych w gatsby-plugin-mdx umożliwia atakującemu wykonanie złośliwego kodu.
CVSS
8.1
EPSS
2.0%
Exploit
poc
Vendor
gatsbyjs
Opis źródłowy (NVD)
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this vulnerability is possible when passing input in both webpack (MDX files in src/pages or MDX file imported as a component in frontend / React code) and data mode (querying MDX nodes via GraphQL). Workaround: If an older version of gatsby-plugin-mdx must be used, input passed into the plugin should be sanitized ahead of processing.
deserialization exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 2.0% |
| Opublikowano (NVD) | 2022-06-10 20:15:08 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-29 15:50:31 UTC |
Referencje
- https://drive.google.com/file/d/1EoCzbwTWOM8-fjvwMbH3bqcZ2iKksxTW/view?usp=sharing ([email protected]) [Exploit, Third Party Advisory]
- https://github.com/gatsbyjs/gatsby/pull/35830 ([email protected]) [Exploit, Patch, Third Party Advisory]
- https://github.com/gatsbyjs/gatsby/pull/35830/commits/f214eb0694c61e348b2751cecd1aace2046bc46e ([email protected]) [Patch, Third Party Advisory]
- https://snyk.io/vuln/SNYK-JS-GATSBYPLUGINMDX-2405699 ([email protected]) [Exploit, Third Party Advisory]