Security features bypass in vm2 - CVE-2023-37466

 

Security features bypass in vm2 - CVE-2023-37466

Published: August 30, 2023 / Updated: October 25, 2024


Vulnerability identifier: #VU80135
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-37466
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper validation of user-supplied input within the Promise handler. A remote attacker can pass specially crafted data to the application, bypass sanitization with `@@species` accessor property to escape the sandbox and run arbitrary code.


Affected software

vm2
Multicluster Engine for Kubernetes
IBM Cloud Pak for Multicloud Management
Red Hat Advanced Cluster Management for Kubernetes
Unified OSS Console Assurance Monitoring (UOCAM)
App Connect Enterprise Certified Container
IBM Observability with Instana
IBM App Connect Enterprise

How to mitigate CVE-2023-37466

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

vm2 - update to 3.10.0
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.3.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.6.7, 2.8.1
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.10
App Connect Enterprise Certified Container - addressed in versions 5.0.10, 9.1.0
IBM Observability with Instana - update to 256

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins