Show plain JSON{"id": "CVE-2020-1900", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2021-03-11T01:15:14.490", "references": [{"url": "https://github.com/facebook/hhvm/commit/c1c4bb0cf9e076aafaf4ff3515556ef9faf906f3", "tags": ["Patch", "Third Party Advisory"], "source": "cve-assign@fb.com"}, {"url": "https://hhvm.com/blog/2020/06/30/security-update.html", "tags": ["Vendor Advisory"], "source": "cve-assign@fb.com"}, {"url": "https://github.com/facebook/hhvm/commit/c1c4bb0cf9e076aafaf4ff3515556ef9faf906f3", "tags": ["Patch", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://hhvm.com/blog/2020/06/30/security-update.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "cve-assign@fb.com", "description": [{"lang": "en", "value": "CWE-416"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-416"}]}], "descriptions": [{"lang": "en", "value": "When unserializing an object with dynamic properties HHVM needs to pre-reserve the full size of the dynamic property array before inserting anything into it. Otherwise the array might resize, invalidating previously stored references. This pre-reservation was not occurring in HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0."}, {"lang": "es", "value": "Cuando se anula la serializaci\u00f3n de un objeto con propiedades din\u00e1micas, HHVM necesita reservar previamente el tama\u00f1o completo de la matriz de propiedades din\u00e1micas antes de insertar algo en ella. De lo contrario, la matriz podr\u00eda cambiar de tama\u00f1o, invalidando las referencias almacenadas previamente. Esta reserva previa no estaba ocurriendo en HHVM versiones anteriores a v4.32.3, entre las versiones 4.33.0 y 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62 .0"}], "lastModified": "2024-11-21T05:11:34.540", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2372F3F-5757-4097-BA67-61D7597F6D65", "versionEndExcluding": "4.32.3"}, {"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E83916FC-54F0-4A1B-99AD-0B81774170EE", "versionEndExcluding": "4.56.1", "versionStartIncluding": "4.33.0"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.57.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4F80C7A6-7FD9-4EAB-8533-F5C8ABF9F258"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.58.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2006DF19-68B4-4139-AAAF-7F81B9742DA7"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.58.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A9D0CEF-7EC2-421B-A45D-48D9663DB60B"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.59.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "169B4C73-75D5-46FD-BADB-384ABFB9A6C9"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.60.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A48FC296-D7B6-4B58-A386-9F5F5F6294AF"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.61.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5F702D76-27C2-4798-BF3C-242906E8E697"}, {"criteria": "cpe:2.3:a:facebook:hhvm:4.62.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC078675-9A81-4B74-8818-0FFE9AF66296"}], "operator": "OR"}]}], "sourceIdentifier": "cve-assign@fb.com"}