Exploitation Summary
EIP tracks 2 public exploits for CVE-2021-38297. PoCs published by gkrishnan724, paras98.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-38297, demonstrating memory corruption in a WebAssembly (WASM) environment. The exploit leverages Go-based WASM modules to manipulate memory and extract sensitive data, showcasing the vulnerability's impact.
Description
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
Exploits (2)
This repository contains a functional proof-of-concept exploit for CVE-2021-38297, demonstrating memory corruption in a WebAssembly (WASM) environment. The exploit leverages Go-based WASM modules to manipulate memory and extract sensitive data, showcasing the vulnerability's impact.
This repository contains a functional proof-of-concept exploit for CVE-2021-38297, demonstrating memory corruption in Go WebAssembly (WASM) applications. The exploit leverages unsafe pointer manipulation to read arbitrary memory locations, potentially leading to information disclosure or further exploitation.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H