vendor:
jruby-sandbox
by:
joernchen
8,8
CVSS
HIGH
Bypassing of Sandbox Protection
749
CWE
Product Name: jruby-sandbox
Affected Version From: jruby-sandbox <= 0.2.2
Affected Version To: jruby-sandbox <= 0.2.2
Patch Exists: YES
Related CWE: N/A
CPE: a:omghax:jruby-sandbox
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Phenoelit Advisory
jruby-sandbox aims to allow safe execution of user given Ruby code within a JRuby runtime. However via import of Java classes it is possible to circumvent those protections and execute arbitrary code outside the sandboxed environment.
Mitigation:
Upgrade to version 0.2.3