CVE-2024-23742

A

n issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a victim's machine.

Configurations

Configuration 1 (hide)

cpe:2.3:a:loom:loom:*:*:*:*:*:macos:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://github.com/V3x0r/CVE-2024-23742 - Third Party Advisory () https://github.com/V3x0r/CVE-2024-23742 - Third Party Advisory
References () https://www.electronjs.org/blog/statement-run-as-node-cves - () https://www.electronjs.org/blog/statement-run-as-node-cves -

18 Oct 2024, 15:35

Type Values Removed Values Added
CWE CWE-94

Information

Published : 2024-01-28 03:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23742

Mitre link : CVE-2024-23742

CVE.ORG link : CVE-2024-23742


JSON object : View

Products Affected
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')