JSer.info #652 - Node.jsã®node:vmã¢ã¸ã¥ã¼ã«ã¯Sandbox(ä¿¡ç¨ã§ããªãã³ã¼ãã®å®è¡ç°å¢)ã¨ãã¦ã¯å©ç¨ã§ãã¾ããããvm2ã¯node:vmãã©ãããã¦Sandboxãæä¾ããã¢ã¸ã¥ã¼ã«ã§ããã ä»åãvm2ã®ä»çµã¿çã«ä¿®æ£ã§ããªãSandboxã«é¢ããèå¼±æ§ãçºè¦ããããããã¡ã³ããã³ã¹ãçµäºãããã¨ã宣è¨ããã¦ãã¾ããèå¼±æ§ã®è©³ç´°ã¯ã¾ã å ¬éããã¦ãã¾ããããSandboxãç ´ããã¨ãã§ããèå¼±æ§ã§ãPoCã¯8æããã«å ¬éãããäºå®ã§ãã Discontinued · Issue #533 · patriksimek/vm2 vm2 Sandbox Escape vulnerability · CVE-2023-37466 · GitHub Advisory Database Sandboxæ©è½ã欲ããå ´åã¯ãQuickJSãWebAssemblyã«ã³ã³ãã¤


{{#tags}}- {{label}}
{{/tags}}