2023-08-16 23:55:30 +00:00
{
"id" : "CVE-2023-38894" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-08-16T22:15:13.397" ,
2023-08-17 14:00:32 +00:00
"lastModified" : "2023-08-17T12:53:44.537" ,
"vulnStatus" : "Awaiting Analysis" ,
2023-08-16 23:55:30 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A Prototype Pollution issue in Cronvel Tree-kit v.0.7.4 and before allows a remote attacker to execute arbitrary code via the extend function."
}
] ,
"metrics" : { } ,
"references" : [
{
"url" : "http://tree-kit.com" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://github.com/cronvel/tree-kit" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://www.code-intelligence.com/blog/treekit-prototype-pollution-cve-2023-38894" ,
"source" : "cve@mitre.org"
}
]
}