CVE-2024-27936: Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping
(updated )
A maliciously crafted permission request can show the spoofed permission prompt by inserting a broken ANSI escape sequence into the request contents.
References
- github.com/advisories/GHSA-m4pq-fv2w-6hrw
- github.com/denoland/deno
- github.com/denoland/deno/commit/78d430103a8f6931154ddbbe19d36f3b8630286d
- github.com/denoland/deno/commit/7e6b94231290020b55f1d08fb03ea8132781abc5
- github.com/denoland/deno/security/advisories/GHSA-m4pq-fv2w-6hrw
- nvd.nist.gov/vuln/detail/CVE-2024-27936
Detect and mitigate CVE-2024-27936 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →