DaftDoris / newsdesk

https://newsdesk.daftdoris.com
MIT License
2 stars 1 forks source link

Update dependency vm2 to 3.9.18 [SECURITY] #756

Closed renovate[bot] closed 1 year ago

renovate[bot] commented 1 year ago

Mend Renovate

This PR contains the following updates:

Package Change
vm2 3.9.17 -> 3.9.18

GitHub Vulnerability Alerts

CVE-2023-32314

A sandbox escape vulnerability exists in vm2 for versions up to 3.9.17. It abuses an unexpected creation of a host object based on the specification of Proxy.

Impact

A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.

Patches

This vulnerability was patched in the release of version 3.9.18 of vm2.

Workarounds

None.

References

PoC - https://gist.github.com/arkark/e9f5cf5782dec8321095be3e52acf5ac

For more information

If you have any questions or comments about this advisory:

Thanks to @​arkark (Takeshi Kaneko) of GMO Cybersecurity by Ierae, Inc. for disclosing this vulnerability.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



Automerge: Enabled

cloudflare-workers-and-pages[bot] commented 1 year ago

Deploying with  Cloudflare Pages  Cloudflare Pages

Latest commit: d789c8c
Status: ✅  Deploy successful!
Preview URL: https://d97d3505.newsdesk.pages.dev
Branch Preview URL: https://renovate-npm-vm2-vulnerabili.newsdesk.pages.dev

View logs

sonarcloud[bot] commented 1 year ago

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

cypress[bot] commented 1 year ago

Passing run #2143 ↗︎

0 24 1 0 Flakiness 0

Details:

Merge d789c8c34f75f56793b7a424395dc795cc68190c into abc7c95e9f44949853cb1cb467d2...
Project: newsdesk Commit: e446e889ea ℹ️
Status: Passed Duration: 06:39 💡
Started: May 16, 2023 12:43 AM Ended: May 16, 2023 12:50 AM

This comment has been generated by cypress-bot as a result of this project's GitHub integration settings.