MEDIUM4.2
GHSA-93c7-2942-3h47
ChakraCore information disclosure vulnerability
Quick fix
GHSA-93c7-2942-3h47 — Microsoft.ChakraCore: upgrade to the fixed version with the command below.
dotnet add package Microsoft.ChakraCore --version 1.11.1Details
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Microsoft.ChakraCore
Introduced in:
0Fixed in: 1.11.1Fix
dotnet add package Microsoft.ChakraCore --version 1.11.1References
- https://nvd.nist.gov/vuln/detail/CVE-2018-8315[ADVISORY]
- https://github.com/chakra-core/ChakraCore/pull/5688[WEB]
- https://github.com/chakra-core/ChakraCore/commit/e03b3e30160ac5846b246931634962ce6bd1db83[WEB]
- https://github.com/chakra-core/ChakraCore[PACKAGE]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8315[WEB]
- https://web.archive.org/web/20210124203128/http://www.securityfocus.com/bid/105251[WEB]
- https://web.archive.org/web/20211206083609/https://securitytracker.com/id/1041623[WEB]