First published: Sun May 01 2022(Updated: )
Node.js jailed module could allow a remote attacker to bypass security restrictions, caused by a flaw in the Node.js jailed module. By sending a specially-crafted request, an attacker could exploit this vulnerability to perform sandbox bypass to access the main application.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Jailed Project Jailed | ||
IBM Planning Analytics | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23923 has been classified with a high severity due to its potential to allow remote attackers to bypass security restrictions.
To remediate CVE-2022-23923, it is recommended to update the Jailed module to the latest version where this vulnerability is patched.
CVE-2022-23923 affects the Jailed module in Node.js and IBM Planning Analytics versions up to 2.0.
CVE-2022-23923 can enable sandbox bypass attacks, allowing attackers to access the main application.
CVE-2022-23923 impacts all versions of the Jailed module and IBM Planning Analytics up to version 2.0.