QID 378375
Date Published: 2023-04-12
QID 378375: vm2 NPM Package Remote Code Execution (RCE) Vulnerability (GHSA-7jxr-cg7f-gpgv)
vm2 was not properly handling host objects passed to Error.prepareStackTrace in case of unhandled async errors.
Affected Versions:
vm2 NPM package versions prior to 3.9.15
QID Detection Logic (Authenticated):
This QID checks for vulnerable version of vm2 npm package installed globally. The QID runs the "npm list -g --silent" command and checks the file "/usr/local/lib/node_modules/vm2/package.json" to look for vulnerable versions of vm2.
Note:
NPM packages can be installed anywhere as a developer/production dependency. This QID can only detect vm2 packages that are installed globally. For Microsoft Windows, this QID checks for installed packages within the '%systemdrive%\Users\Administrator' directory.
Successful exploitation of the vulnerability may result in remote code execution.
- GHSA-7jxr-cg7f-gpgv -
github.com/advisories/GHSA-7jxr-cg7f-gpgv
CVEs related to QID 378375
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7jxr-cg7f-gpgv |
|