Improper Control of Dynamically-Managed Code Resources in vm2 - CVE-2023-29017

 

Improper Control of Dynamically-Managed Code Resources in vm2 - CVE-2023-29017

Published: April 10, 2023 / Updated: May 17, 2023


Vulnerability identifier: #VU74606
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29017
CWE-ID: CWE-913
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to escape sandbox restrictions.

The vulnerability exists due to improper handling of host objects passed to "Error.prepareStackTrace" in case of unhandled async errors. A remote attacker can pass specially crafted input to the application, escape sandbox restrictions and execute arbitrary code on the host.


Affected software

vm2
backstage/techdocs-common
API Gateway
API Manager
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2023-29017

Install updates from vendor's website.

vm2 - update to 3.9.15
API Gateway - update to May 2023
API Manager - update to May 2023
backstage/techdocs-common - update to 1.13.0
Multicluster Engine for Kubernetes - addressed in versions 2.0.7, 2.1.5, 2.2.3
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.7, 2.6.4, 2.7.3
IBM Cloud Pak for Watson AIOps - update to 3.7.1
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins