Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wfwf-xhx7-3whj

Опубликовано: 10 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.

EPSS

Процентиль: 40%
0.00181
Низкий

7.2 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.2
nvd
почти 3 года назад

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.

EPSS

Процентиль: 40%
0.00181
Низкий

7.2 High

CVSS3

Дефекты

CWE-74