Описание
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
Ссылки
- Release Notes
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.10.5 (исключая)
cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 57%
0.00921
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-693
CWE-653
Связанные уязвимости
CVSS3: 9.8
redhat
3 месяца назад
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
CVSS3: 9.8
fstec
3 месяца назад
Уязвимость функции VM.run() библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнить произвольный код
EPSS
Процентиль: 57%
0.00921
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-693
CWE-653