GHSA-f67q-wr6w-23jq
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
Details
A wrong assumption made when handling ECMAScript's `AsyncGenerator` operations can cause an uncaught exception on certain scripts.
## Details
Boa's implementation of `AsyncGenerator` makes the assumption that the state of an `AsyncGenerator` object cannot change while resolving a promise created by methods of `AsyncGenerator` such as `%AsyncGeneratorPrototype%.next`, `%AsyncGeneratorPrototype%.return`, or `%AsyncGeneratorPrototype%.throw`. However, a carefully constructed code could trigger a state transition from a getter method for the promise's `then` property, which causes the engine to fail an assertion of this assumption, causing an uncaught exception. This could be used to create a Denial Of Service attack in applications that run arbitrary ECMAScript code provided by an external user.
## Patches
Version 0.19.0 is patched to correctly handle this case.
## Workarounds
Users unable to upgrade to the patched version would want to use [`std::panic::catch_unwind`](https://doc.rust-lang.org/std/panic/fn.catch_unwind.html) to ensure any exceptions caused by the engine don't impact the availability of the main application.
## References
- https://github.com/boa-dev/boa/commit/69ea2f52ed976934bff588d6b566bae01be313f7 - https://github.com/tc39/ecma262/security/advisories/GHSA-g38c-wh3c-5h9r
Are you affected?
Enter the version of the package you're using.
Affected packages
0.16Fixed in: 0.19.0Upgrade boa_engine to 0.19.0 or newer (ecosystem crates.io).
References
- https://github.com/boa-dev/boa/security/advisories/GHSA-f67q-wr6w-23jq[WEB]
- https://github.com/tc39/ecma262/security/advisories/GHSA-g38c-wh3c-5h9r[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-43367[ADVISORY]
- https://github.com/boa-dev/boa/commit/69ea2f52ed976934bff588d6b566bae01be313f7[WEB]
- https://github.com/boa-dev/boa[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2024-0444.html[WEB]