CVE-2023-26919
Published Apr 10, 2023
Last updated 2 years ago
Overview
- Description
- delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.2
- Impact score
- 2.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- CWE-74
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:javadelight:nashorn_sandbox:0.2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36B6F6D6-AB93-4DE2-944B-40499DA0AE1C" }, { "criteria": "cpe:2.3:a:javadelight:nashorn_sandbox:0.2.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "261E31E2-4ABF-4F34-A3E3-DB878B460123" } ], "operator": "OR" } ] } ]