Sandbox Bypass Leading to Arbitrary Code Execution in constantinople
Critical severity
GitHub Reviewed
Published
Jun 14, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jun 14, 2019
Published to the GitHub Advisory Database
Jun 14, 2019
Last updated
Jan 9, 2023
Versions of
constantinople
prior to 3.1.1 are vulnerable to a sandbox bypass which can lead to arbitrary code execution.Recommendation
Update to version 3.1.1 or later.
References