Security features bypass in vm2 - CVE-2023-37903

 

Security features bypass in vm2 - CVE-2023-37903

Published: August 15, 2023


Vulnerability identifier: #VU79504
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2023-37903
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to unspecified error. An attacker with code execution primitive inside the context of vm2 sandbox can use the Node.js custom inspect function to escape the sandbox and run arbitrary code.


Affected software

vm2
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
Unified OSS Console Assurance Monitoring (UOCAM)
App Connect Enterprise Certified Container
IBM Observability with Instana
IBM App Connect Enterprise

How to mitigate CVE-2023-37903

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

vm2 - update to 3.10.3
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7, 2.3.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.7.7, 2.8.1
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.10
App Connect Enterprise Certified Container - addressed in versions 5.0.10, 9.1.0
IBM Observability with Instana - update to 256

External References

Related Security Bulletins