
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-13991 affects JerryScript version 2.2.0, where attackers can hijack the flow of control by controlling a register in vm/opcodes.c (CVE Details).
The vulnerability exists in the spread arguments handling mechanism within JerryScript's virtual machine implementation. The issue stems from incorrect release of spread arguments during execution, where the stack pointer was incremented early in the opfunc_spread_arguments function, resulting in a state where one of the arguments was not properly freed. This caused memory leaks and potential control flow hijacking (GitHub PR).
The vulnerability allows attackers to hijack the control flow of the application, which could lead to arbitrary code execution within the context of the JerryScript engine. The issue manifests through memory corruption and can result in segmentation faults or program crashes (GitHub Issue).
The vulnerability can be triggered through specially crafted JavaScript code that utilizes spread arguments. Multiple proof-of-concept examples demonstrate successful exploitation, resulting in segmentation faults and program crashes (GitHub Issue, GitHub Issue).
The issue was fixed in a patch that corrects the release of spread arguments by properly handling the stack pointer increment timing in the opfunc_spread_arguments function. Users should upgrade to a version containing the fix (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."