Security features bypass in vm2 - CVE-2023-32314
Published: May 25, 2023
Vulnerability identifier: #VU76527
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32314
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to an unexpected creation of a host object based on the specification of `Proxy`. A remote attacker can escape sandbox restrictions and gain remote code execution rights on the host.
Affected software
vm2
backstage/techdocs-common
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
IBM Cloud Pak for Watson AIOps
backstage/techdocs-common
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-32314
Install updates from vendor's website.
vm2 - update to 3.9.18
backstage/techdocs-common - update to 1.14.0
Multicluster Engine for Kubernetes - addressed in versions 2.0.9, 2.1.7, 2.2.4
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.9, 2.6.6, 2.7.4
IBM Cloud Pak for Watson AIOps - update to 4.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.7, 8.2.0
backstage/techdocs-common - update to 1.14.0
Multicluster Engine for Kubernetes - addressed in versions 2.0.9, 2.1.7, 2.2.4
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.9, 2.6.6, 2.7.4
IBM Cloud Pak for Watson AIOps - update to 4.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.7, 8.2.0
External References
Related Security Bulletins
- Multiple vulnerabilities in vm2 for Node.js
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.7
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.6
- Security features bypass in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.5
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.0
- backstage update for vm2
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management