CVE Vulnerabilities

CVE-2024-23682

Trust Boundary Violation

Published: Jan 19, 2024 | Modified: Nov 21, 2024
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the supposedly sandboxed code.

Weakness

The product mixes trusted and untrusted data in the same data structure or structured message.

Affected Software

Name Vendor Start Version End Version
Artemis_java_test_sandbox Ls1intum * 1.8.0 (excluding)

References