CVE-2023-39584

Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:*
cpe:2.3:a:hexo:hexo:7.0.0:rc1:*:*:*:node.js:*:*
cpe:2.3:a:hexo:hexo:7.0.0:rc2:*:*:*:node.js:*:*

History

21 Nov 2024, 08:15

Type Values Removed Values Added
References () https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49 - Third Party Advisory () https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49 - Third Party Advisory
References () https://github.com/hexojs/hexo/issues/5250 - Issue Tracking, Third Party Advisory () https://github.com/hexojs/hexo/issues/5250 - Issue Tracking, Third Party Advisory
References () https://www.gem-love.com/2023/07/25/hexo%E5%8D%9A%E5%AE%A2%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E5%92%8C%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/#undefined - Third Party Advisory () https://www.gem-love.com/2023/07/25/hexo%E5%8D%9A%E5%AE%A2%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E5%92%8C%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/#undefined - Third Party Advisory

26 Sep 2024, 18:35

Type Values Removed Values Added
CWE CWE-22

12 Sep 2023, 15:12

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:hexo:hexo:7.0.0:rc1:*:*:*:node.js:*:*
cpe:2.3:a:hexo:hexo:*:*:*:*:*:node.js:*:*
cpe:2.3:a:hexo:hexo:7.0.0:rc2:*:*:*:node.js:*:*
References (MISC) https://www.gem-love.com/2023/07/25/hexo%E5%8D%9A%E5%AE%A2%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E5%92%8C%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/#undefined - (MISC) https://www.gem-love.com/2023/07/25/hexo%E5%8D%9A%E5%AE%A2%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E5%92%8C%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/#undefined - Third Party Advisory
References (MISC) https://github.com/hexojs/hexo/issues/5250 - (MISC) https://github.com/hexojs/hexo/issues/5250 - Issue Tracking, Third Party Advisory
References (MISC) https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49 - (MISC) https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49 - Third Party Advisory
First Time Hexo hexo
Hexo

08 Sep 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-08 13:15

Updated : 2024-11-21 08:15


NVD link : CVE-2023-39584

Mitre link : CVE-2023-39584

CVE.ORG link : CVE-2023-39584


JSON object : View

Products Affected

hexo

  • hexo
CWE
NVD-CWE-noinfo CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')