CVE-2024-23683

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ls1intum:artemis_java_test_sandbox:*:*:*:*:*:*:*:*

History

26 Jan 2024, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
References () https://github.com/advisories/GHSA-883x-6fch-6wjx - () https://github.com/advisories/GHSA-883x-6fch-6wjx - Exploit, Third Party Advisory
References () https://github.com/ls1intum/Ares/commit/af4f28a56e2fe600d8750b3b415352a0a3217392 - () https://github.com/ls1intum/Ares/commit/af4f28a56e2fe600d8750b3b415352a0a3217392 - Patch
References () https://github.com/ls1intum/Ares/issues/15#issuecomment-996449371 - () https://github.com/ls1intum/Ares/issues/15#issuecomment-996449371 - Issue Tracking
References () https://github.com/ls1intum/Ares/releases/tag/1.7.6 - () https://github.com/ls1intum/Ares/releases/tag/1.7.6 - Release Notes
References () https://github.com/ls1intum/Ares/security/advisories/GHSA-883x-6fch-6wjx - () https://github.com/ls1intum/Ares/security/advisories/GHSA-883x-6fch-6wjx - Exploit, Vendor Advisory
References () https://vulncheck.com/advisories/vc-advisory-GHSA-883x-6fch-6wjx - () https://vulncheck.com/advisories/vc-advisory-GHSA-883x-6fch-6wjx - Third Party Advisory
First Time Ls1intum
Ls1intum artemis Java Test Sandbox
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:ls1intum:artemis_java_test_sandbox:*:*:*:*:*:*:*:*
Summary
  • (es) Las versiones de Artemis Java Test Sandbox inferiores a 1.7.6 son vulnerables a un escape de la sandbox cuando un atacante crea una subclase especial de InvocationTargetException. Un atacante puede abusar de este problema para ejecutar Java arbitrario cuando una víctima ejecuta el código supuestamente aislado.

19 Jan 2024, 22:52

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-19 21:15

Updated : 2024-01-26 15:17


NVD link : CVE-2024-23683

Mitre link : CVE-2024-23683

CVE.ORG link : CVE-2024-23683


JSON object : View

Products Affected

ls1intum

  • artemis_java_test_sandbox