CVE-2023-32314
Sandbox Escape
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
A flaw was found in the vm2 sandbox. When a host object is created based on the specification of Proxy, an attacker can bypass the sandbox protections. This may allow an attacker to run remote code execution on the host running the sandbox. This vulnerability impacts the confidentiality, integrity, and availability of the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-05-08 CVE Reserved
- 2023-05-15 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-10-25 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://github.com/patriksimek/vm2/releases/tag/3.9.18 | Release Notes |
URL | Date | SRC |
---|---|---|
https://gist.github.com/arkark/e9f5cf5782dec8321095be3e52acf5ac | 2024-08-02 |
URL | Date | SRC |
---|---|---|
https://github.com/patriksimek/vm2/commit/d88105f99752305c5b8a77b63ddee3ec86912daf | 2023-05-24 |
URL | Date | SRC |
---|---|---|
https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5 | 2023-05-24 | |
https://access.redhat.com/security/cve/CVE-2023-32314 | 2023-05-30 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2208376 | 2023-05-30 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vm2 Project Search vendor "Vm2 Project" | Vm2 Search vendor "Vm2 Project" for product "Vm2" | < 3.9.18 Search vendor "Vm2 Project" for product "Vm2" and version " < 3.9.18" | node.js |
Affected
|