CVE-2019-10761
vm2 before 3.6.11 vulnerable to sandbox escape
8.3
HIGH
CVSS 3.1
EPSS 0.97%
描述
This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule property of the host code running the script allowing it to spawn a child_process and execute arbitrary code.
如何修補 CVE-2019-10761
要修補 CVE-2019-10761,請將受影響套件升級到下列已修補版本。
- —升級至 3.6.11 或更新版本
CVE-2019-10761 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 3.6.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |