CVE-2023-26919
PoC —CVSS 3.1
7.2 high
EPSS
<1%p47
Published
()
Modified
Description
delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
- Vendors
- javadelight
- Products
- nashorn sandbox
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.