Описание
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
A flaw was found in vm2, an open-source sandbox for Node.js. An attacker can exploit this vulnerability by running malicious code within the VM.run() function, allowing them to escape the sandbox and gain access to the host process. This can lead to arbitrary code execution on the host system, enabling the attacker to run host commands without any host cooperation.
Отчет
This is an Important flaw in vm2, an open-source Node.js sandbox, that allows for arbitrary code execution due to a sandbox escape. An attacker can run malicious code within the VM.run() function to gain access to the host process and execute commands without host cooperation.
Red Hat Developer Hub product is not affected by this vulnerability, as the affected vm2 package is used only as a development dependency and should not be reachable by the user in the final product image. For Red Hat Ansible Portal, this component is already shipping the version 3.10.5 of vm2 which contains the fix for this vulnerability, thus it's not affected.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Developer Hub | rhdh/backstage-community-plugin-catalog-backend-module-scaffolder-relation-processor | Not affected | ||
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | ||
| Self-service automation portal 2 | ansible-automation-platform/automation-portal | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and runs host commands with zero host cooperation. This issue has been patched in version 3.10.5.
Уязвимость функции VM.run() библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3