CVE-2024-23681
Artemis Java Test Sandbox Libary Load Escape
Severity Score
8.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
Las versiones de Artemis Java Test Sandbox anteriores a 1.11.2 son vulnerables a un escape de la sandbox cuando un atacante carga librerías que no son de confianza utilizando System.load o System.loadLibrary. Un atacante puede abusar de este problema para ejecutar Java arbitrario cuando una víctima ejecuta el código supuestamente aislado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-01-19 CVE Reserved
- 2024-01-19 CVE Published
- 2024-01-27 EPSS Updated
- 2024-11-13 CVE Updated
- 2024-11-13 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vulncheck.com/advisories/vc-advisory-GHSA-98hq-4wmw-98w9 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/advisories/GHSA-98hq-4wmw-98w9 | 2024-11-13 | |
https://github.com/ls1intum/Ares/security/advisories/GHSA-98hq-4wmw-98w9 | 2024-11-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ls1intum Search vendor "Ls1intum" | Artemis Java Test Sandbox Search vendor "Ls1intum" for product "Artemis Java Test Sandbox" | < 1.11.2 Search vendor "Ls1intum" for product "Artemis Java Test Sandbox" and version " < 1.11.2" | - |
Affected
|