Description
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
References
https://github.com/patriksimek/vm2/commit/b4f6e2bd2c4a1ef52fc4483d8e35f28bc4481886
PatchThird Party Advisory
https://github.com/patriksimek/vm2/issues/363
Third Party Advisory
https://github.com/patriksimek/vm2/releases/tag/3.9.4
Release NotesThird Party Advisory
https://security.netapp.com/advisory/ntap-20211029-0010/
Third Party Advisory
https://snyk.io/vuln/SNYK-JS-VM2-1585918
ExploitThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
10 · Critical
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2021-10-18T17:15:07.790
3 years agoLast modified
2022-06-28T14:11:45.273
3 years ago