CVE-2021-23555

The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*

History

22 Feb 2022, 20:12

Type Values Removed Values Added
References (CONFIRM) https://snyk.io/vuln/SNYK-JS-VM2-2309905 - (CONFIRM) https://snyk.io/vuln/SNYK-JS-VM2-2309905 - Exploit, Patch, Third Party Advisory
References (CONFIRM) https://github.com/patriksimek/vm2/commit/532120d5cdec7da8225fc6242e154ebabc63fe4d - (CONFIRM) https://github.com/patriksimek/vm2/commit/532120d5cdec7da8225fc6242e154ebabc63fe4d - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*

11 Feb 2022, 21:15

Type Values Removed Values Added
Summary The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine. The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

11 Feb 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-11 20:15

Updated : 2024-02-04 22:29


NVD link : CVE-2021-23555

Mitre link : CVE-2021-23555

CVE.ORG link : CVE-2021-23555


JSON object : View

Products Affected

vm2_project

  • vm2