Risk | Medium |
Patch available | NO |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-37903 |
CWE-ID | CWE-254 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
vm2 Web applications / Modules and components for CMS |
Vendor | Patrik Simek |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU79504
Risk: Medium
CVSSv3.1: 7.5 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:U/RC:C]
CVE-ID: CVE-2023-37903
CWE-ID:
CWE-254 - Security Features
Exploit availability: No
DescriptionThe vulnerability allows an attacker to bypass implemented security restrictions.
The vulnerability exists due to unspecified error. An attacker with code execution primitive inside the context of vm2 sandbox can use the Node.js custom inspect function to escape the sandbox and run arbitrary code.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsvm2: 3.9.0 - 3.9.19
External linkshttp://github.com/patriksimek/vm2/security/advisories/GHSA-g644-9gfx-q4q4
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.