CVE-2023-45311 describes a critical vulnerability in the fsevents project, specifically versions prior to 1.2.11. The vulnerability stems from its dependency on a potentially compromised S3 URL, which could allow an adversary to execute arbitrary code if a JavaScript project using fsevents distributed code obtained from that URL during a period of adversarial control. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a significant risk due to its network-based attack vector, low attack complexity, and high potential for impact across confidentiality, integrity, and availability. While the URL is reportedly no longer under adversarial control, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.11CPE matchmatch criteria | cpe:2.3:a:fsevents_project:fsevents:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.