vm2 vulnerable to Sandbox Escape before v3.9.11
Published Sep 6, 2022
10.0
CRITICALCVSS 3.1
EPSS 47.87%
Description
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.
Affected products
-
- Version < 3.9.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Patriksimek | Vm2 | n/a |
|
- < 3.9.11
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Affected | n/a |
vm2
npm
Introduced 0 Fixed 3.9.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | vm2 | 0 | 3.9.11 |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-36067 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2124794 Issue Tracking
- https://github.com/advisories/GHSA-mrgp-mrhc-5jrq Advisory
- https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71 ExploitThird Party Advisory
- https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164 PatchThird Party Advisory
- https://github.com/patriksimek/vm2/issues/467 Issue TrackingThird Party Advisory
- https://github.com/patriksimek/vm2/security/advisories/GHSA-mrgp-mrhc-5jrq PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36067
- https://security.netapp.com/advisory/ntap-20221017-0002/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-36067
- https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-36067 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2124794 | Issue Tracking | |
| https://github.com/advisories/GHSA-mrgp-mrhc-5jrq | Advisory | |
| https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71 | ExploitThird Party Advisory | |
| https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164 | PatchThird Party Advisory | |
| https://github.com/patriksimek/vm2/issues/467 | Issue TrackingThird Party Advisory | |
| https://github.com/patriksimek/vm2/security/advisories/GHSA-mrgp-mrhc-5jrq | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36067 | ||
| https://security.netapp.com/advisory/ntap-20221017-0002/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-36067 | ||
| https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.