-
CVSS Score
-The commit d97375c explicitly addresses CVE-2017-11905 by modifying IRBuilderAsmJs::CreateLabel. The vulnerability stemmed from reusing label instructions based solely on their existence, without checking if they corresponded to the correct bytecode offset. This flaw in JIT optimization could allow attackers to manipulate control flow and corrupt memory, leading to arbitrary code execution. The direct link between the commit, CVE ID, and the security patch provides high confidence in this assessment.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Microsoft.ChakraCore | nuget | < 1.7.5 | 1.7.5 |
Ongoing coverage of React2Shell