Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-23555

Опубликовано: 11 фев. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

A flaw was found in vm2, where the sandbox can be bypassed via direct access to host error objects generated by node internals during the generation of stack traces. This flaw allows an attacker to execute arbitrary code on the host machine.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-562

EPSS

Процентиль: 86%
0.02876
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

CVSS3: 9.8
github
больше 4 лет назад

Sandbox bypass in vm2

EPSS

Процентиль: 86%
0.02876
Низкий

9.8 Critical

CVSS3