Описание
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fromEntries, it is possible to construct {[p]: Function} where p is any constructible property. This vulnerability is fixed in 0.8.34.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.8.34 (исключая)
cpe:2.3:a:nyariv:sandboxjs:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 43%
0.00547
Низкий
10 Critical
CVSS3
Дефекты
CWE-94
Связанные уязвимости
CVSS3: 10
fstec
5 месяцев назад
Уязвимость библиотеки SandboxJS, связанная с неверным управлением генерацией кода, позволяющая нарушителю выйти из изолированной программной среды
EPSS
Процентиль: 43%
0.00547
Низкий
10 Critical
CVSS3
Дефекты
CWE-94