SB2022091301 - Remote code execution in vm2 for Node.js
Published: September 13, 2022 Updated: April 11, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper access control (CVE-ID: CVE-2022-36067)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper access restrictions. A remote attacker can bypass the sandbox protections and execute arbitrary code on the host running the sandbox.
Remediation
Install update from vendor's website.
References
- https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164
- https://github.com/patriksimek/vm2/issues/467
- https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71
- https://github.com/patriksimek/vm2/security/advisories/GHSA-mrgp-mrhc-5jrq