Security restrictions bypass in vm2



Published: 2023-08-15
Risk Medium
Patch available NO
Number of vulnerabilities 1
CVE-ID CVE-2023-37903
CWE-ID CWE-254
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
vm2
Web applications / Modules and components for CMS

Vendor Patrik Simek

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Security features bypass

EUVDB-ID: #VU79504

Risk: Medium

CVSSv3.1: 7.5 [CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:U/RC:C]

CVE-ID: CVE-2023-37903

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to unspecified error. An attacker with code execution primitive inside the context of vm2 sandbox can use the Node.js custom inspect function to escape the sandbox and run arbitrary code.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

vm2: 3.9.0 - 3.9.19

External links

http://github.com/patriksimek/vm2/security/advisories/GHSA-g644-9gfx-q4q4


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###