Lucene search

K
f5F5F5:K000134725
HistoryMay 22, 2023 - 12:00 a.m.

K000134725 : vm2 vulnerability CVE-2023-29017

2023-05-2200:00:00
my.f5.com
15
sandbox
remote code execution
host object
threat actor
vulnerability
unhandled async errors
patch

AI Score

7.9

Confidence

Low

EPSS

0.017

Percentile

87.9%

Security Advisory Description

vm2 is a sandbox that can run untrusted code with whitelisted Node’s built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to Error.prepareStackTrace in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds. (CVE-2023-29017)

Impact

There is no impact; F5 products are not affected by this vulnerability.

AI Score

7.9

Confidence

Low

EPSS

0.017

Percentile

87.9%