Security features bypass in vm2 - CVE-2023-32314

 

Security features bypass in vm2 - CVE-2023-32314

Published: May 25, 2023


Vulnerability identifier: #VU76527
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32314
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an unexpected creation of a host object based on the specification of `Proxy`. A remote attacker can escape sandbox restrictions and gain remote code execution rights on the host.


Affected software

vm2
backstage/techdocs-common
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2023-32314

Install updates from vendor's website.

vm2 - update to 3.9.18
backstage/techdocs-common - update to 1.14.0
Multicluster Engine for Kubernetes - addressed in versions 2.0.9, 2.1.7, 2.2.4
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.9, 2.6.6, 2.7.4
IBM Cloud Pak for Watson AIOps - update to 4.1.0
App Connect Enterprise Certified Container - addressed in versions 5.0.7, 8.2.0

External References

Related Security Bulletins