THREAT OPS › Threat News › [GHSA] GHSA-m5w8-4gq2-6f8x (critical) — vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
[GHSA] GHSA-m5w8-4gq2-6f8x (critical) — vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
GHSA-m5w8-4gq2-6f8x Severity: critical CVE: None
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
# NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
**CWE**: CWE-200 (Exposure of Sensi
MITRE ATT&CK techniques
Indicators of compromise
- 8.8.4.4ipv4
- 185.12.64.2ipv4
- 185.12.64.1ipv4
- registry.npmjs.orgdomain
Original source: https://github.com/advisories/GHSA-m5w8-4gq2-6f8x