vm2 is a sandbox that can run untrusted code with Nodes built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node inspect
method and edit options for console.log
. As a result a threat actor can edit options for the console.log
command. This vulnerability was patched in the release of version 3.9.18
of vm2
. Users are advised to upgrade. Users unable to upgrade may make the inspect
method readonly with vm.readonly(inspect)
after creating a vm.
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vm2 | Vm2_project | * | 3.9.18 (excluding) |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-agent-service-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-apiserver-network-proxy-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-image-service-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-agent-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-reporter-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-aws-encryption-provider-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-agent-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-aws-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-azure-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-kubevirt-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-clusterclaims-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-curator-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-clusterlifecycle-state-metrics-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-console-mce-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-discovery-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hive-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-addon-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-deployment-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-klusterlet-operator-bundle-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-managedcluster-import-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-managed-serviceaccount-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-multicloud-manager-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-must-gather-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-operator-bundle-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-placement-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-provider-credential-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-registration-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-registration-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-work-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-agent-service-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-apiserver-network-proxy-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-image-service-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-agent-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-assisted-installer-reporter-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-aws-encryption-provider-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-agent-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-aws-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-azure-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-api-provider-kubevirt-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-clusterclaims-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-curator-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-clusterlifecycle-state-metrics-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-proxy-addon-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-cluster-proxy-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-console-mce-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-discovery-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hive-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-addon-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-deployment-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-hypershift-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-klusterlet-operator-bundle-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-managedcluster-import-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-managed-serviceaccount-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-multicloud-manager-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-must-gather-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-operator-bundle-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-placement-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-provider-credential-controller-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-registration-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-registration-operator-container | * |
Multicluster Engine for Kubernetes | RedHat | multicluster-engine-work-container | * |
Multicluster engine for Kubernetes 2.2 for RHEL 8 | RedHat | multicluster-engine/console-mce-rhel8:v2.2.4-4 | * |
Multicluster engine for Kubernetes 2.2 for RHEL 8 | RedHat | multicluster-engine/multicluster-engine-console-mce-rhel8:v2.2.4-4 | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-cluster-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-governance-policy-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-grafana-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-must-gather-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-operator-bundle-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-config-reloader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-volsync-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cert-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-backup-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-proxy-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | config-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | console-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | endpoint-monitoring-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-propagator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-spec-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-status-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-template-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grafana-dashboard-loader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | iam-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-client-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-rbac-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-state-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | management-ingress-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | metrics-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicloud-integrations-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-repo-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-observability-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-application-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-channel-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-subscription-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | node-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-alertmanager-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rbac-query-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | redisgraph-tls-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-aggregator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | submariner-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-receive-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-governance-policy-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-grafana-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-must-gather-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-operator-bundle-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-config-reloader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-prometheus-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-volsync-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cert-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-backup-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | config-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | console-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | endpoint-monitoring-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-propagator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-spec-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-status-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-template-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grafana-dashboard-loader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | iam-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-client-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-rbac-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-state-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | management-ingress-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | metrics-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicloud-integrations-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-repo-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-observability-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-application-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-channel-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-subscription-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | node-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-alertmanager-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rbac-query-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | redisgraph-tls-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-aggregator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | submariner-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-receive-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8 | RedHat | rhacm2/console-rhel8:v2.7.4-4 | * |