GHSA-g6w6-h933-4rc5

    Dashboard / Vulnerabilities / GHSA-g6w6-h933-4rc5

    GHSA-g6w6-h933-4rc5

    Published: 3 Aug 2023Last Modified: 3 Aug 2023

    Summary: Soketi was exposed to Sandbox Escape vulnerability via vm2

    Details: ### Impact _What kind of vulnerability is it? Who is impacted?_ Anyone who might have used Soketi with the `cluster` driver (or through PM2). ### Patches _Has the problem been patched? What versions should users upgrade to?_ Get the latest version of Soketi. ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ None. It's advised to upgrade to the latest version. ### References _Are there any links users can visit to find out more?_ - https://github.com/advisories/GHSA-cchq-frgv-rjh5 - https://github.com/patriksimek/vm2/issues/533 - https://github.com/Unitech/pm2/issues/5643

    Affected packages

    Package

    Name: @soketi/soketi

    Purl: pkg:npm/%40soketi/soketi

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.6.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-g6w6-h933-4rc5 | CVE-DB