CVE-2023-26919
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L
Exploitability: 3.9 / Impact: 2.7
Source: NVD
Description
delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
Affected (2)
Products: Javadelight: Nashorn Sandbox
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 0.2.4 |
References (2)
Source: cve@mitre.org
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory
Timeline
No history available yet.