Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Vulnerability Description
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's prototype chain and reach e.constructor.constructor for arbitrary host command execution. This issue is fixed in version 3.11.6.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
动态管理代码资源的控制不恰当
Vulnerability Title
Patrik Simek vm2 处理逻辑错误漏洞
Vulnerability Description
Patrik Simek vm2是Patrik Simek个人开发者的一个运行不受信任代码的沙箱环境。 Patrik Simek vm2 3.11.6之前版本存在处理逻辑错误漏洞,该漏洞源于lib/bridge.js和lib/setup-sandbox.js未能阻止通过Function.prototype.call的危险主机原型getter和setter修改器进行堆叠间接引用,可能导致沙箱代码切断主机固有原型链并执行任意主机命令。
CVSS Information
N/A
Vulnerability Type
N/A