vm2: Sandbox Breakout in VM2
Hello 👋
The Oxeye research team has found a sandbox breakout vulnerability in VM2. We would like to share the in-depth analysis with you so the vulnerability can be fixed. We tried to contact security@integromat.com
but didn’t get any response.
Could you please share with me an email address to keep the issue private?
Best, Oxeye Research Team
About this issue
- Original URL
- State: closed
- Created 2 years ago
- Comments: 18 (3 by maintainers)
Hi @XmiliaH! Wanted to check whether you would consider creating a GitHub Security Advisory for this? It’s a pretty lightweight process and a nice way to make sure updates are picked up by users as soon as possible.
Unfortunately, I can’t see any configuration of roles in this repository.
I have created the empty advisory and shared access with both @XmiliaH and @oxeye-daniel.
After some exploration. I find the secrets from https://github.com/patriksimek/vm2/commit/d9a7f3cc995d3d861e1380eafb886cb3c5e2b873.
some reference
Just requested the CVE and published the advisory. Let me know if there’s anything else to do. Thank you @oxeye-daniel for reporting the issue and @XmiliaH for a quick fix!
Thanks for reaching out, you can contact me under <redacted>.
@XmiliaH - do you happen to know who the admins are for this repo and would have the necessary permissions? Thanks in advance!