Vulnerability Details CVE-2020-24345
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.7%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2020-24345
-
cpe:2.3:a:jerryscript:jerryscript:-
-
cpe:2.3:a:jerryscript:jerryscript:1.0
-
cpe:2.3:a:jerryscript:jerryscript:2.0
-
cpe:2.3:a:jerryscript:jerryscript:2.1.0
-
cpe:2.3:a:jerryscript:jerryscript:2.2.0
-
cpe:2.3:a:jerryscript:jerryscript:2.3.0