SB2023081515 - Security restrictions bypass in vm2



SB2023081515 - Security restrictions bypass in vm2

Published: August 15, 2023

Security Bulletin ID SB2023081515
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2023-37903)

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to unspecified error. An attacker with code execution primitive inside the context of vm2 sandbox can use the Node.js custom inspect function to escape the sandbox and run arbitrary code.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.