Friday, March 24, 2023
Learning Code
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#
No Result
View All Result
Learning Code
No Result
View All Result
Home JavaScript

A Critical RCE Bug Found in Widely Used vm2 JavaScript Sandbox

learningcode_x1mckf by learningcode_x1mckf
October 20, 2022
in JavaScript
0
A Critical RCE Bug Found in Widely Used vm2 JavaScript Sandbox
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


You might also like

Toolkit Allows JavaScript Devs to Program Embedded Devices – The New Stack

Select data value from grandparent div? – JavaScript – SitePoint

How to Handle Errors in JavaScript – Programming – MUO – MakeUseOf

Sandbreak – A Critical Remote Code Execution Bug Found in Widely Used vm2 JavaScript Sandbox

Within the JavaScript sandbox library vm2, the cybersecurity analysts at Oxeye analysis workforce have just lately discovered a extreme RCE flaw dubbed, “Sandbreak.”

By way of the NPM package deal repository, the vm2 sandbox library achieves a complete of 16 million downloads every month because it is among the hottest JavaScript sandboxes.

CVE-2022-36067 is the CVE ID that has been assigned to the vm2 vulnerability. Consequently, the CVSS has assigned a severity rating of 10.0 to this vulnerability, which is the best rating attainable.

An attacker can circumvent the vm2 setting by exploiting the CVE-2022-36067 vulnerability. After the profitable exploitation of this vulnerability, the attacker is ready to run shell instructions on the system of the sufferer operating inside a sandboxed setting.

EHA

Flaw Profile

  • CVE ID: CVE-2022-36067
  • Description: Distant execution vulnerability in vm2 sandbox library
  • CVSS Rating: 10
  • Severity: Essential
  • Standing: Patched

Technical Evaluation

As of August 28, 2022, model 3.9.11 has been launched to handle this vital vulnerability. With the built-in module permit listed, vm2 is among the hottest Node libraries for operating untrusted code throughout the digital machine.

The vm2 maintainers are believed to have carried out a Node.js function in an insecure method, which has been the foundation reason for this vulnerability.

An error that happens in VM2 might be personalized to be able to generate an object known as a “CallSite”, which can be utilized to customise the decision stack. 

As a consequence of this, it’s attainable to execute instructions and entry the worldwide objects of Node.js exterior of the sandbox by creating these objects.

Oxeye’s researchers found a method to bypass the mitigation mechanism utilized by the library’s authors, which served as a way of limiting the potential of this occurring previously. Whereas to attain this, the “prepareStackTrace” technique might be personalized to be able to carry out this motion.

Suggestion

VM2 was notified about this vital problem a few days after Oxeye found it on August 16, 2022. A model of three.9.11, which addresses this problem, was launched on August 28, 2022, by the authors of the VM2 library.

Functions that make use of the Sandbox with none patches would possibly face alarming penalties because of the exploitation of CVE-2022-36067.

In response to this, cybersecurity consultants have strongly advisable that customers ought to instantly set up model 3.9.11 of the software program, to be able to defend themselves.

Block extra Intense DDoS Assaults Under 5 Minutes, All the time Allow Multi-layered Safety.



Source link

Share30Tweet19
learningcode_x1mckf

learningcode_x1mckf

Recommended For You

Toolkit Allows JavaScript Devs to Program Embedded Devices – The New Stack

by learningcode_x1mckf
March 23, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Toolkit Allows JavaScript Devs to Program Embedded Devices  The New Stack Source link

Read more

Select data value from grandparent div? – JavaScript – SitePoint

by learningcode_x1mckf
March 23, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Select data value from grandparent div? - JavaScript  SitePoint Source link

Read more

How to Handle Errors in JavaScript – Programming – MUO – MakeUseOf

by learningcode_x1mckf
March 23, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

How to Handle Errors in JavaScript - Programming  MUO - MakeUseOf Source link

Read more

How to Use the Javascript Slice Method – hackernoon.com

by learningcode_x1mckf
March 23, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

How to Use the Javascript Slice Method  hackernoon.com Source link

Read more

Clean Code in JavaScript – SitePoint

by learningcode_x1mckf
March 23, 2023
0
Google expands open source bounties, will soon support Javascript fuzzing too – ZDNet

Clean Code in JavaScript  SitePoint Source link

Read more
Next Post
Indonesia wants 'Java Man', art back from Dutch museums – Arab News

Indonesia wants 'Java Man', art back from Dutch museums - Arab News

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

It Is Time To Shun C, C++ Languages For New Projects: Microsoft Azure CTO – Amazon, Android, Azure, Chrome, Delhi, Google, Intel, Languages, Microsoft, Projects, Python, Shun, Windows – It is time to shun C, C++ languages for new projects: Microsoft Azure CTO

It Is Time To Shun C, C++ Languages For New Projects: Microsoft Azure CTO – Amazon, Android, Azure, Chrome, Delhi, Google, Intel, Languages, Microsoft, Projects, Python, Shun, Windows – It is time to shun C, C++ languages for new projects: Microsoft Azure CTO

October 20, 2022
UIColor best practices in Swift

UIColor best practices in Swift

October 8, 2022
Time limit for notify – JavaScript – SitePoint Forums

Adding class if div is empty – JavaScript – SitePoint Forums

November 9, 2022

Browse by Category

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

RECENT POSTS

  • Java Developer Survey Reveals Increased Need for Java … – PR Newswire
  • What You Should Definitely Pay Attention to When Hiring Java Developers – Modern Diplomacy
  • Java Web Frameworks Software Market Research Report 2023 … – Los Alamos Monitor

CATEGORIES

  • C#
  • C++
  • Java
  • JavaScript
  • Python
  • Swift

© 2022 Copyright Learning Code

No Result
View All Result
  • Home
  • JavaScript
  • Java
  • Python
  • Swift
  • C++
  • C#

© 2022 Copyright Learning Code

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?