Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-32313

Опубликовано: 15 мая 2023
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node inspect method and edit options for console.log. As a result a threat actor can edit options for the console.log command. This vulnerability was patched in the release of version 3.9.18 of vm2. Users are advised to upgrade. Users unable to upgrade may make the inspect method readonly with vm.readonly(inspect) after creating a vm.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
Версия до 3.9.18 (исключая)

EPSS

Процентиль: 65%
0.005
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
redhat
больше 2 лет назад

vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a threat actor can edit options for the `console.log` command. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. Users unable to upgrade may make the `inspect` method readonly with `vm.readonly(inspect)` after creating a vm.

CVSS3: 5.3
github
больше 2 лет назад

vm2 vulnerable to Inspect Manipulation

EPSS

Процентиль: 65%
0.005
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-74
NVD-CWE-noinfo