Saturday, April 1, 2023
Learning Code
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
Learning Code
No Result
View All Result
Home JavaScript

Researchers Detail Critical RCE Flaw Reported in Popular vm2 JavaScript Sandbox

learningcode_x1mckf by learningcode_x1mckf
October 11, 2022
in JavaScript
0
Researchers Detail Critical RCE Flaw Reported in Popular vm2 JavaScript Sandbox
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

You might also like

4 Packages for Working With Date and Time in JavaScript – MUO – MakeUseOf

Understanding the Power of Proxy in JavaScript – hackernoon.com

JavaScript vs. TypeScript: What's the difference? – TheServerSide.com


vm2 JavaScript Sandbox

A now-patched safety flaw within the vm2 JavaScript sandbox module might be abused by a distant adversary to interrupt out of safety obstacles and carry out arbitrary operations on the underlying machine.

“A menace actor can bypass the sandbox protections to realize distant code execution rights on the host operating the sandbox,” GitHub said in an advisory revealed on September 28, 2022.

CyberSecurity

The problem, tracked as CVE-2022-36067 and codenamed Sandbreak, carries a most severity score of 10 on the CVSS vulnerability scoring system. It has been addressed in version 3.9.11 launched on August 28, 2022.

vm2 is a popular Node library that is used to run untrusted code with allowlisted built-in modules. It is also probably the most extensively downloaded software program, accounting for almost 3.5 million downloads per week.

vm2 JavaScript Sandbox

The shortcoming is rooted within the error mechanism in Node.js to flee the sandbox, in keeping with software safety agency Oxeye, which discovered the flaw.

Which means that profitable exploitation of CVE-2022-36067 might allow an attacker to bypass the vm2 sandbox surroundings and run shell instructions on the system internet hosting the sandbox.

CyberSecurity

In mild of the essential nature of the vulnerability, customers are advisable to replace to the newest model as quickly as potential to mitigate potential threats.

“Sandboxes serve totally different functions in fashionable purposes, equivalent to inspecting connected information in electronic mail servers, offering an extra safety layer in internet browsers, or isolating actively operating purposes in sure working programs,” Oxeye stated.

“Given the character of the use instances for sandboxes, it is clear that the vm2 vulnerability can have dire penalties for purposes that use vm2 with out patching.”





Source link

Share30Tweet19
learningcode_x1mckf

learningcode_x1mckf

Recommended For You

4 Packages for Working With Date and Time in JavaScript – MUO – MakeUseOf

by learningcode_x1mckf
April 1, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

4 Packages for Working With Date and Time in JavaScript  MUO - MakeUseOf Source link

Read more

Understanding the Power of Proxy in JavaScript – hackernoon.com

by learningcode_x1mckf
April 1, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Understanding the Power of Proxy in JavaScript  hackernoon.com Source link

Read more

JavaScript vs. TypeScript: What's the difference? – TheServerSide.com

by learningcode_x1mckf
April 1, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

JavaScript vs. TypeScript: What's the difference?  TheServerSide.com Source link

Read more

JetBrains updates IDEs for Java, JavaScript, Ruby – InfoWorld

by learningcode_x1mckf
March 31, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

JetBrains updates IDEs for Java, JavaScript, Ruby  InfoWorld Source link

Read more

Virtru Announces First Ever FIPS 140-2 Validated JavaScript … – GlobeNewswire

by learningcode_x1mckf
March 30, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Virtru Announces First Ever FIPS 140-2 Validated JavaScript ...  GlobeNewswire Source link

Read more
Next Post
With Java 19, Oracle boosts developer productivity with an eye on the future

With Java 19, Oracle boosts developer productivity with an eye on the future

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Java News Roundup: Sequenced Collections for JDK 21, Vector API … – InfoQ.com

March 16, 2023
VP, Baznas disburse microfinance aid at Central Java mosque

VP, Baznas disburse microfinance aid at Central Java mosque

November 18, 2022
A New Javascript Runtime Fresh Out Of The Oven

A New Javascript Runtime Fresh Out Of The Oven

September 23, 2022

Browse by Category

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

RECENT POSTS

  • So why did they decide to call it Java? – InfoWorld
  • Senior Java Developer – IT-Online
  • 4 Packages for Working With Date and Time in JavaScript – MUO – MakeUseOf

CATEGORIES

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

© 2022 Copyright Learning Code

No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#

© 2022 Copyright Learning Code

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?