vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host proto getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with process context, bypassing code generation restrictions.
The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend:1791242697 | * |
| Red Hat Developer Hub 1.10 | RedHat | rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend:1791251282 | * |