RHSA-2023:1893: Critical: Multicluster Engine for Kubernetes 2.0 hotfix security update for console
Security Fix(es) CVE-2023-29017 vm2: Sandbox Escape CVE-2023-29199 vm2: Sandbox Escape CVE-2023-30547 vm2: Sandbox Escape when exception sanitization
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2023:1893?
RHSA-2023:1893 addresses three vulnerabilities related to sandbox escape in the vm2 package, including CVE-2023-29017, CVE-2023-29199, and CVE-2023-30547.
What is the severity of RHSA-2023:1893?
The vulnerabilities in RHSA-2023:1893 are classified with high severity due to their potential for sandbox escape.
How do I fix RHSA-2023:1893?
To mitigate the vulnerabilities in RHSA-2023:1893, you should update the vm2 package to the latest version provided by your vendor.
Are there any known exploits for RHSA-2023:1893?
As of now, there are no publicly known exploits specifically targeting the vulnerabilities outlined in RHSA-2023:1893.
What systems are affected by RHSA-2023:1893?
RHSA-2023:1893 affects systems running the vm2 package, which is commonly used in Node.js applications.