GHSA-2jjq-x548-rhpv

Suggest an improvement
Source
https://github.com/advisories/GHSA-2jjq-x548-rhpv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-2jjq-x548-rhpv/GHSA-2jjq-x548-rhpv.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-2jjq-x548-rhpv
Aliases
Published
2022-09-30T22:59:03Z
Modified
2023-11-01T04:59:48.075154Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
isolated-vm has vulnerable CachedDataOptions in API
Details

Impact

If the untrusted v8 cached data is passed to the API through CachedDataOptions, the attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation to warn users that they should not accept cachedData payloads from a user.

Database specific
{
    "severity": "CRITICAL",
    "cwe_ids": [
        "CWE-20",
        "CWE-287",
        "CWE-693"
    ],
    "github_reviewed": true,
    "nvd_published_at": "2022-09-29T18:15:00Z",
    "github_reviewed_at": "2022-09-30T22:59:03Z"
}
References

Affected packages

npm / isolated-vm

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.7

Database specific

last_known_affected_version_range
"<= 4.3.6"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-2jjq-x548-rhpv/GHSA-2jjq-x548-rhpv.json"