delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-04-10T00:00:00
Updated: 2024-08-02T12:01:31.039Z
Reserved: 2023-02-27T00:00:00
Link: CVE-2023-26919
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2023-04-10T16:15:07.200
Modified: 2023-04-14T17:03:19.027
Link: CVE-2023-26919
Redhat
No data.