CVE-2021-23449: Sandbox Bypass
Published Oct 18, 2021
·Updated
This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitrary code on the host machine.
Affected Software
1 affected component
Vm2 Project Vm2 Node.js<3.9.4
Remediation
Event History
Oct 18, 2021
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-23449?
CVE-2021-23449 is considered a critical vulnerability that allows for arbitrary code execution due to prototype pollution.
2
How do I fix CVE-2021-23449?
To mitigate CVE-2021-23449, you should upgrade the vm2 package to version 3.9.4 or later.
3
What versions of vm2 are affected by CVE-2021-23449?
All versions of vm2 prior to 3.9.4 are affected by CVE-2021-23449.
4
What attack vector is associated with CVE-2021-23449?
CVE-2021-23449 is associated with a Prototype Pollution attack vector.
5
Can CVE-2021-23449 lead to data breaches?
Yes, CVE-2021-23449 can potentially lead to data breaches by enabling arbitrary code execution on the host machine.