GHSA-6jg8-7333-554w

Suggest an improvement
Source
https://github.com/advisories/GHSA-6jg8-7333-554w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6jg8-7333-554w
Published
2019-10-04T17:56:12Z
Modified
2021-09-02T16:40:48Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Sandbox Breakout in realms-shim
Details

Versions of realms-shim prior to 1.2.0 are vulnerable to a Sandbox Breakout. Reflect.construct can be used on the sandboxed Function constructor to reach the prototypes of the primal Realm, which may allow an attacker to escape the sandbox and execute arbitrary code.

Recommendation

Upgrade to version 1.2.0 or later.

Database specific
{
    "cwe_ids": [],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:19:30Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

npm / realms-shim

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json"

npm / ses

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.6.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-6jg8-7333-554w/GHSA-6jg8-7333-554w.json"