FirebaseFirestoreInternalBinary is vulnerable to Use-After-Free
15
Low Risk
Affected versions of the FirebaseFirestoreInternalBinary package are vulnerable to a use-after-free vulnerability in the FormatArg class. This occurs due to improper usage of the absl::AlphaNum class, which Firestore employs in an unintended manner. As a result, memory that has already been freed may be accessed, potentially leading to undefined behavior, crashes, or security exploits.
You are affected if you are using a version that falls within the vulnerable range.
FirebaseFirestoreInternalBinary is vulnerable to Use-After-Free in versions 0.14.0 - 11.7.0.
Upgrade the FirebaseFirestoreInternalBinary library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant