vm2是捷克Patrik Simek个人开发者的一个 Node.js 的高级虚拟机/沙盒。以使用列入白名单的 Node 内置模块运行不受信任的代码。 vm2 3.9.17之前版本存在注入漏洞,该漏洞源于异常清理存在漏洞,攻击者利用该漏洞可以引发未清理的主机异常,该异常可用于逃逸沙箱并在主机上下文中运行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| patriksimek | vm2 | < 3.9.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PoC Exploit for VM2 Sandbox Escape Vulnerability | https://github.com/rvizx/CVE-2023-30547 | POC Details |
| 2 | PoC to CVE-2023-30547 (Library vm2) | https://github.com/user0x1337/CVE-2023-30547 | POC Details |
| 3 | Tool for exploring CVE-2023-30547 | https://github.com/Cur1iosity/CVE-2023-30547 | POC Details |
| 4 | None | https://github.com/junnythemarksman/CVE-2023-30547 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet