PT-2023-2909 · Vm2 · Vm2
Arkark
+1
·
Publicado
2023-05-15
·
Atualizado
2026-06-04
·
CVE-2023-32314
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
vm2 versions up to and including 3.9.17
Description
A sandbox escape issue exists in vm2, allowing a threat actor to bypass sandbox protections and gain remote code execution rights on the host. This is achieved by abusing an unexpected creation of a host object based on the specification of
Proxy. The vulnerability can be exploited by a remote attacker to execute arbitrary code.Recommendations
For versions up to and including 3.9.17, upgrade to version 3.9.18 or later to patch the vulnerability. As a temporary workaround, consider restricting access to the
Proxy specification until a patch is applied. There are no known workarounds for this vulnerability. Users are advised to upgrade to a patched version to mitigate the risk.Exploit
Correção
Improper Handling of Exceptional Conditions
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vm2