CVE-2022-24783: Sandbox bypass leading to arbitrary code execution in Deno
Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell code. This vulnerability does not affect users of Deno Deploy. The vulnerability has been patched in Deno 1.20.3. There is no workaround. All users are recommended to upgrade to 1.20.3 immediately.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24783?
CVE-2022-24783 is a vulnerability in Deno, a runtime for JavaScript and TypeScript, that allows a malicious actor to bypass permission checks and execute arbitrary shell code.
What is the severity of CVE-2022-24783?
CVE-2022-24783 has a severity level of critical (10).
Which versions of Deno are affected by CVE-2022-24783?
The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are affected by CVE-2022-24783.
How can a malicious actor exploit CVE-2022-24783?
A malicious actor controlling the code executed in a Deno runtime can exploit CVE-2022-24783 to bypass permission checks and execute arbitrary shell code.
Is there a fix available for CVE-2022-24783?
Yes, a fix is available for CVE-2022-24783. Update Deno to version 1.20.3 or later to mitigate the vulnerability.