[Security] CVE-2024-38112 and WelsonJS framework #141
gnh1201
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
[Security] CVE-2024-38112 and WelsonJS framework
We have identified that code snippets included in the WelsonJS framework were found in an attack case that exploited the CVE-2024-38112 and CVE-2024-43461 security vulnerability. The attacker utilized part of the
app.hta
file.To clarify, we want to emphasize that there is no connection between this attack or the attacker and the WelsonJS project.
The attacker demonstrated the use of VBScript and VBScript obfuscation in the attack.
This does not align with the WelsonJS project, which is entirely based on JavaScript, nor does it correspond to the code protection methods supported by WelsonJS.
Additionally, most of the functionalities we provide are aimed at helping system administrators or security analysts from a defensive standpoint, rather than being used for attacks.
The WelsonJS project utilizes JavaScript and is developed with future compatibility in mind, ensuring support even when the runtime changes.
Thank you.
Related links
Want to share your thoughts?
We run a Discord channel (#welsonjs, Catswords OSS) and ActivityPub @[email protected], and you’re always welcome to join us! Feel free to ask questions or share your opinions anytime.
Beta Was this translation helpful? Give feedback.
All reactions