Rewterz
Rewterz Threat Alert – Quasar RAT aka CinaRAT – Active IOCs
April 10, 2023
Rewterz
Rewterz Threat Advisory – Multiple Apache Airflow Vulnerabilities
April 10, 2023

Rewterz Threat Advisory – CVE-2023-29017 – Node.js vm2 module Vulnerability

Severity

High

Analysis Summary

CVE-2023-29017

Node.js vm2 module could allow a remote attacker to execute arbitrary code on the system, caused by a sandbox bypass flaw in the handling host objects passed to Error.prepareStackTrace. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.

Impact

  • Code Execution

Indicators Of Compromise

CVE

  • CVE-2023-29017

Affected Vendors

Node.js

Affected Products

  • Node.js vm2 3.9.14

Remediation

Upgrade to the latest version of vm2, available from the vm2 GIT Repository. 

vm2 GIT Repository