delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
References
| Link | Resource |
|---|---|
| https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
| https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Feb 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/javadelight/delight-nashorn-sandbox/issues/135 - Exploit, Issue Tracking, Vendor Advisory |
14 Apr 2023, 17:03
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-74 | |
| CPE | cpe:2.3:a:javadelight:nashorn_sandbox:0.2.4:*:*:*:*:*:*:* cpe:2.3:a:javadelight:nashorn_sandbox:0.2.5:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
| References | (MISC) https://github.com/javadelight/delight-nashorn-sandbox/issues/135 - Exploit, Issue Tracking, Vendor Advisory | |
| First Time |
Javadelight nashorn Sandbox
Javadelight |
10 Apr 2023, 16:47
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-04-10 16:15
Updated : 2025-02-11 18:15
NVD link : CVE-2023-26919
Mitre link : CVE-2023-26919
JSON object : View
Products Affected
javadelight
- nashorn_sandbox
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
