[MAVEN:GHSA-23RX-79R7-6CPX] Sandbox escape in Artemis Java Test Sandbox

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.

Package Affected Version
pkg:maven/de.tum.in.ase/artemis-java-test-sandbox < 1.7.6
ID
MAVEN:GHSA-23RX-79R7-6CPX
Severity
moderate
URL
https://github.com/advisories/GHSA-23rx-79r7-6cpx
Published
2024-01-19T21:30:36
(8 months ago)
Modified
2024-01-23T14:34:39
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/de.tum.in.ase/artemis-java-test-sandbox de.tum.in.ase artemis-java-test-sandbox < 1.7.6
Fixed pkg:maven/de.tum.in.ase/artemis-java-test-sandbox de.tum.in.ase artemis-java-test-sandbox = 1.7.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...