CVE-2024-23683
HIGH8.2EPSS 0.18%Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
Published: 1/19/2024Modified: 2/3/2026
Description
## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-883x-6fch-6wjx. This link is maintained to preserve external references. ## Original Description Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
Affected packages (2)
- Maven/de.tum.in.ase:artemis-java-test-sandboxfrom 0, < 1.7.6
- Maven/de.tum.in.ase:artemis-java-test-sandboxfrom 0, < 1.7.6
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
References (8)
- ADVISORYhttps://github.com/advisories/GHSA-883x-6fch-6wjx
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-23683
- PATCHhttps://github.com/ls1intum/Ares
- WEBhttps://github.com/ls1intum/Ares/commit/af4f28a56e2fe600d8750b3b415352a0a3217392
- WEBhttps://github.com/ls1intum/Ares/issues/15#issuecomment-996449371
- WEBhttps://github.com/ls1intum/Ares/releases/tag/1.7.6
- WEBhttps://github.com/ls1intum/Ares/security/advisories/GHSA-883x-6fch-6wjx
- WEBhttps://vulncheck.com/advisories/vc-advisory-GHSA-883x-6fch-6wjx