All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.
References
Link | Resource |
---|---|
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2441254 | Exploit Third Party Advisory |
https://snyk.io/vuln/SNYK-JS-JAILED-2391490 | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-05-01 09:15
Updated : 2022-05-11 08:52
NVD link : CVE-2022-23923
Mitre link : CVE-2022-23923
JSON object : View
CWE
Products Affected
jailed_project
- jailed