Code Red: 4 Critical SandboxJS Flaws (CVSS 10.0) Allow Host Takeover
ID: 3629d04e-205e-5d76-93cc-8e8aa11c0a7f
STIX ID: report--3629d04e-205e-5d76-93cc-8e8aa11c0a7f
Feed Name: securityonline.info
Threat Score
A quartet of critical vulnerabilities in SandboxJS (all CVSS 10.0) allow attackers to break out of the JavaScript sandbox and execute arbitrary code on the host by abusing unwrapped function return values, overwriting Map.prototype.has, shadowing hasOwnProperty to bypass whitelist checks, and exploiting a TOCTOU property key validation bug; maintainers patched the issues in v0.8.29, and affected versions are 0.8.28 and earlier.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
