Fiche vulnérabilité
CVE-2022-23923 : faille critique jailed project jailed (CVSS 9.8)
Description
All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 mai 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- jailed project jailed