PT-2022-4708 · Backstage+2 · Backstage+2

Oxeye-Daniel

·

Published

2022-09-06

·

Updated

2026-05-06

·

CVE-2022-36067

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions prior to 3.9.11
Description The issue is related to insufficient resource control with dynamic management in the vm2 library, allowing a remote attacker to execute arbitrary code by bypassing sandbox protections. The vulnerability affects the vm2 sandbox, which can run untrusted code with whitelisted Node's built-in modules. It is estimated that over 500 instances of Backstage, a popular developer portal, are vulnerable to this issue, with many of them accessible without authentication due to default deployment settings. The vulnerability was patched in version 3.9.11 of vm2.
Recommendations For versions prior to 3.9.11, update to version 3.9.11 or later to resolve the issue. As a temporary workaround, consider disabling the use of the vm2 sandbox until a patch is applied. Restrict access to the vm2 module to minimize the risk of exploitation. Avoid using the vm2 sandbox to run untrusted code until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05598
CVE-2022-36067
GHSA-MRGP-MRHC-5JRQ

Affected Products

Backstage
Node
Vm2