CVE-2023-3224Code Injection in Nuxt

CWE-94Code Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
2.1%
top 15.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13

Description

Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDnuxt/nuxt3.4.03.4.3
npmnuxt/nuxt3.4.03.4.3
CVEListV5nuxt/nuxt_nuxtunspecified3.5.3

Patches

🔴Vulnerability Details

2
GHSA
nuxt Code Injection vulnerability2023-06-13
OSV
nuxt Code Injection vulnerability2023-06-13