ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-38856CVE-2024-7965CVE-2024-7971

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38856
Pre-auth RCE via Incorrect Authorization in Apache OFBiz

CVE-2024-38856 is an incorrect authorization flaw (CWE-863) in Apache OFBiz, an open-source ERP and e-commerce platform, affecting all versions through 18.12.14. On deployments where screen definitions do not explicitly verify a user's permissions because they rely on the configuration of the endpoints serving them, unauthenticated endpoints can be made to execute the screens' rendering code. As coverage of the fix describes, this can be leveraged for unauthenticated (pre-auth) remote code execution on the OFBiz server, consistent with the critical 9.8 CVSS score. Any organization running Apache OFBiz 18.12.14 or earlier, especially with the OFBiz web interface exposed to the internet, is affected. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2024-08-27 amid active exploitation reports, and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Upgrade all Apache OFBiz servers to version 18.12.15 or later immediately; the KEV listing requires applying vendor mitigations or discontinuing use within the required deadline, and newer OFBiz releases also address additional 2024 flaws (e.g., CVE-2024-45195), so updating to the latest available version is prudent. Inventory internet-facing OFBiz deployments and restrict unauthenticated access to OFBiz web endpoints where possible. Hunt for signs of exploitation (unexpected screen/view rendering requests to unauthenticated endpoints and follow-on activity on OFBiz hosts), since the flaw is being actively exploited.

9.899% KEV
  • Apache OFBiz through 18.12.14 (fixed in 18.12.15)
moderate~several thousand internet-exposed Apache OFBiz instances
CVE-2024-7971
+1 in the same advisory: …7965
Type Confusion in Google Chromium V8 Enables Heap Corruption via Malicious Pages

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that lets a remote attacker trigger heap corruption through a specially crafted HTML page. The attack is triggered simply by a user loading an attacker-controlled web page, with no other interaction required. Successful exploitation of heap corruption in a browser JavaScript engine typically gives the attacker code execution within the browser process, a common first step toward broader system compromise. All users of Chromium-based browsers are affected, including Google Chrome, Microsoft Edge, Opera, and any other product embedding Chromium V8. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-08-26, confirming active in-the-wild exploitation, and EPSS assigns a 20.7% probability of exploitation within 30 days (97th percentile).

Do: Update all Chromium-based browsers (Chrome, Edge, Opera, Brave) to the vendors' patched releases immediately and verify the installed version via chrome://version or edge://version. Per CISA's KEV required action, apply vendor mitigations or discontinue use if patches are unavailable; until patching completes, treat web browsing on high-value systems with caution and watch for vendors to publish the specific fixed version numbers.

9.6
group max
21% KEV PoC
  • Google Chromium V8 JavaScript engine
  • Google Chrome (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • Microsoft Edge (Chromium-based) All versions built on the affected V8 engine prior to vendor updates (not specified in source data)
  • +1 more
massbillions of users/installations (Chrome alone is estimated at ~3 billion+ users, plus Edge, Opera, Brave and other Chromium browsers)
Full article300 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 bug to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium V8 Inappropriate Implementation Vulnerability CVE-2024-38856 (CVSS score of 8.8) to its Known Exploited Vulnerabilities (KEV) catalog.

This week Google released a security update to address the Chrome zero-day vulnerability CVE-2024-7965 that is actively exploited.

The vulnerability is an Inappropriate implementation issue that resides in Chrome’s V8 JavaScript engine.

“Google is aware that exploits for CVE-2024-7971 and CVE-2024-7965 exist in the wild.” reads the advisory published by the company that did not share details about the attacks exploiting the issue. “Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”.

“We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.”

The security researcher TheDog reported the flaw on 2024-07-30.

Google addressed the vulnerability with the release of 128.0.6613.84/.85 for Windows/macOS and 128.0.6613.84 (Linux). The company will release versions for all users in the Stable Desktop channel over the coming weeks.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by September 18, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/167722/security/u-s-cisa-adds-google-chromium-v8-bug-known-exploited-vulnerabilities-catalog.html