// For flags

CVE-2018-6333

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.

El gestor hhvm-attach deep link en Nuclide no sanea debidamente el parámetro hostname proporcionado durante la renderización. En consecuencia, una URL maliciosa podría utilizarse para renderizar HTML y otro tipo de contenido dentro del contexto del editor, lo cual podría ser encadenado para provocar la ejecución de código. Esto afecta a las versiones de Nuclide anteriores a la v0.290.0.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-26 CVE Reserved
  • 2018-03-16 First Exploit
  • 2018-12-31 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-11-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Facebook
Search vendor "Facebook"
Nuclide
Search vendor "Facebook" for product "Nuclide"
< 0.290.0
Search vendor "Facebook" for product "Nuclide" and version " < 0.290.0"
-
Affected