PT-2022-24856 · Unknown · Isolated-Vm

Laverdet

·

Published

2022-09-29

·

Updated

2023-08-25

·

CVE-2022-39266

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions isolated-vm versions 4.3.6 and prior
Description The issue allows attackers to bypass the sandbox and run arbitrary code in the nodejs process if untrusted v8 cached data is passed to the API through CachedDataOptions. This can be exploited by passing malicious cachedData payloads. Version 4.3.7 updates the documentation to warn users against accepting cachedData payloads from untrusted sources.
Recommendations For versions 4.3.6 and prior, as a temporary workaround, consider restricting the use of CachedDataOptions to prevent the acceptance of untrusted cachedData payloads until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Protection Mechanism Failure

Improper Authentication

RCE

Weakness Enumeration

Related Identifiers

CVE-2022-39266
GHSA-2JJQ-X548-RHPV

Affected Products

Isolated-Vm