Vulnerabilities > CVE-2022-36067 - Improper Control of Dynamically-Managed Code Resources vulnerability in VM2 Project VM2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Related news
- Researchers Detail Critical RCE Flaw Reported in Popular vm2 JavaScript Sandbox (source)
- Critical VM2 flaw lets attackers run code outside the sandbox (source)
- Log4Shell-like code execution hole in popular Backstage dev tool (source)
- Exploit available for critical bug in VM2 JavaScript sandbox library (source)
- New sandbox escape PoC exploit available for VM2 library, patch now (source)
References
- https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873#diff-b1a515a627d820118e76d0e323fe2f0589ed50a1eacb490f6c3278fe3698f164
- https://github.com/patriksimek/vm2/issues/467
- https://github.com/patriksimek/vm2/blob/master/lib/setup-sandbox.js#L71
- https://github.com/patriksimek/vm2/security/advisories/GHSA-mrgp-mrhc-5jrq
- https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067
- https://security.netapp.com/advisory/ntap-20221017-0002/