delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
References
Link | Resource |
---|---|
https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/javadelight/delight-nashorn-sandbox/issues/135 - Exploit, Issue Tracking, Vendor Advisory |
Information
Published : 2023-04-10 16:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-26919
Mitre link : CVE-2023-26919
CVE.ORG link : CVE-2023-26919
JSON object : View
Products Affected
javadelight
- nashorn_sandbox
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')