delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
References
Link | Resource |
---|---|
https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
https://github.com/javadelight/delight-nashorn-sandbox/issues/135 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
11 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/javadelight/delight-nashorn-sandbox/issues/135 - Exploit, Issue Tracking, Vendor Advisory |
14 Apr 2023, 17:03
Type | Values Removed | Values Added |
---|---|---|
First Time |
Javadelight nashorn Sandbox
Javadelight |
|
CWE | CWE-74 | |
References | (MISC) https://github.com/javadelight/delight-nashorn-sandbox/issues/135 - Exploit, Issue Tracking, Vendor Advisory | |
CPE | cpe:2.3:a:javadelight:nashorn_sandbox:0.2.4:*:*:*:*:*:*:* cpe:2.3:a:javadelight:nashorn_sandbox:0.2.5:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
10 Apr 2023, 16:47
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-10 16:15
Updated : 2025-02-11 18:15
NVD link : CVE-2023-26919
Mitre link : CVE-2023-26919
JSON object : View
Products Affected
javadelight
- nashorn_sandbox
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')