← Back

CVE-2023-26919

nvd nist
Published: Apr 10, 2023Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Exploitability: 3.9 / Impact: 2.7
Source: NVD

Description

delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.

Affected (2)

1 product
Nashorn Sandbox
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Javadelight
Version 0.2.4
Version 0.2.5

References (2)

Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.