{
  "threat_severity" : "Critical",
  "public_date" : "2023-05-15T00:00:00Z",
  "bugzilla" : {
    "description" : "vm2: Sandbox Escape",
    "id" : "2208376",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2208376"
  },
  "cvss3" : {
    "cvss3_base_score" : "9.8",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-915",
  "details" : [ "vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and including 3.9.17. It abuses an unexpected creation of a host object based on the specification of `Proxy`. As a result a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.18` of `vm2`. Users are advised to upgrade. There are no known workarounds for this vulnerability.", "A flaw was found in the vm2 sandbox. When a host object is created based on the specification of Proxy, an attacker can bypass the sandbox protections. This may allow an attacker to run remote code execution on the host running the sandbox. This vulnerability impacts the confidentiality, integrity, and availability of the system." ],
  "acknowledgement" : "Red Hat would like to thank Takeshi Kaneko (GMO Cybersecurity by Ierae, Inc.) for reporting this issue.",
  "package_state" : [ {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "rhacm2/console-rhel8",
    "cpe" : "cpe:/a:redhat:acm:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2023-32314\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-32314\nhttps://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5" ],
  "name" : "CVE-2023-32314",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}