PT-2023-32964 · Unknown+3 · Isolated-Vm+3

Publicado

2023-09-15

·

Atualizado

2023-09-15

CVSS v3.1

7.6

Alta

VetorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions up to 3.9.19 Directus versions prior to 10.6.0
Description The issue allows attackers to bypass Promise handler sanitization in vm2, enabling them to escape the sandbox and execute arbitrary code. This specifically affects the "Run Script" operation in Directus flows, where code can escape the sandbox and run in the main Node.js context.
Recommendations For vm2 versions up to 3.9.19, update to a version that replaces vm2 with isolated-vm, such as Directus version 10.6.0. For Directus versions prior to 10.6.0, update to version 10.6.0 to replace vm2 with isolated-vm.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GHSA-22RR-F3P8-5GF8

Produtos afetados

Directus
Node.Js
Isolated-Vm
Vm2