Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-23555

Опубликовано: 11 фев. 2022
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Версия до 3.9.6 (исключая)

EPSS

Процентиль: 78%
0.01093
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
redhat
почти 4 года назад

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

CVSS3: 9.8
github
почти 4 года назад

Sandbox bypass in vm2

EPSS

Процентиль: 78%
0.01093
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo