Skip to content

Comments

Remove vulnerable js2py#12

Open
Scrumplex wants to merge 1 commit intovintasoftware:developfrom
Scrumplex:chore/remove-vulnerable-js2py
Open

Remove vulnerable js2py#12
Scrumplex wants to merge 1 commit intovintasoftware:developfrom
Scrumplex:chore/remove-vulnerable-js2py

Conversation

@Scrumplex
Copy link

js2py is potentially vulnerable to RCE. As it is unmaintained it should
just be removed from the tests.

POC: https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28397

js2py is potentially vulnerable to RCE. As it is unmaintained it should
just be removed from the tests.

POC: https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28397

Signed-off-by: Sefa Eyeoglu <contact@scrumplex.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant