GHSA-22rr-f3p8-5gf8

Suggest an improvement
Source
https://github.com/advisories/GHSA-22rr-f3p8-5gf8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-22rr-f3p8-5gf8/GHSA-22rr-f3p8-5gf8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-22rr-f3p8-5gf8
Published
2023-09-15T17:12:42Z
Modified
2023-09-15T17:12:42Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Directus affected by VM2 sandbox escape vulnerability
Details

Impact

In vm2 for versions up to 3.9.19, Promise handler sanitization can be bypassed, allowing attackers to escape the sandbox and run arbitrary code. Within Directus this applies to the "Run Script" operation in flows being able to escape the sandbox running code in the main nodejs context.

Patches

Patched in v10.6.0 by replacing vm2 with isolated-vm

Workarounds

None

References

https://github.com/patriksimek/vm2/security/advisories/GHSA-cchq-frgv-rjh5

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-09-15T17:12:42Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / directus

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.6.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-22rr-f3p8-5gf8/GHSA-22rr-f3p8-5gf8.json"