2 results (0.002 seconds)

CVSS: 7.2EPSS: 0%CPEs: 2EXPL: 1

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process. • https://github.com/javadelight/delight-nashorn-sandbox/issues/135 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 1

An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack. Se ha detectado un problema en Delight Nashorn Sandbox 0.2.0. Se presenta una vulnerabilidad ReDoS que puede ser explotada para lanzar un ataque de denegación de servicio (DoS) • https://github.com/javadelight/delight-nashorn-sandbox/issues/117 • CWE-1333: Inefficient Regular Expression Complexity •