-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description and title directly name the function xmlXIncludeAddNode and the file xinclude.c as the location of the use-after-free vulnerability. Although the commit details could not be fetched to examine the exact lines of code changed, the provided information is specific enough to identify this function as vulnerable. The advisory GHSA-84p5-cqqq-h4gr and CVE-2022-49043 also confirm this. I was unable to fetch the commit information from gitlab, so I am relying on the vulnerability description and advisory information. The confidence is high because the function is explicitly named in the vulnerability description and title.
Ongoing coverage of React2Shell