Логотип exploitDog
bind:CVE-2023-32314
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-32314

Количество 4

Количество 4

redhat логотип

CVE-2023-32314

больше 2 лет назад

vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2023-32314

больше 2 лет назад

vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-whpj-8f3w-67p5

больше 2 лет назад

vm2 Sandbox Escape vulnerability

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2023-02869

больше 2 лет назад

Уязвимость библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-32314

vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 9.8
70%
Средний
больше 2 лет назад
nvd логотип
CVE-2023-32314

vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 9.8
70%
Средний
больше 2 лет назад
github логотип
GHSA-whpj-8f3w-67p5

vm2 Sandbox Escape vulnerability

CVSS3: 9.8
70%
Средний
больше 2 лет назад
fstec логотип
BDU:2023-02869

Уязвимость библиотеки vm2 пакетного менеджера NPM, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
70%
Средний
больше 2 лет назад

Уязвимостей на страницу