René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

82 lines
2.2 KiB
JSON

{
"id": "CVE-2023-26919",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-04-10T16:15:07.200",
"lastModified": "2023-04-14T17:03:19.027",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 7.2,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-74"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:javadelight:nashorn_sandbox:0.2.4:*:*:*:*:*:*:*",
"matchCriteriaId": "36B6F6D6-AB93-4DE2-944B-40499DA0AE1C"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:javadelight:nashorn_sandbox:0.2.5:*:*:*:*:*:*:*",
"matchCriteriaId": "261E31E2-4ABF-4F34-A3E3-DB878B460123"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/javadelight/delight-nashorn-sandbox/issues/135",
"source": "cve@mitre.org",
"tags": [
"Exploit",
"Issue Tracking",
"Vendor Advisory"
]
}
]
}