Description |
This article describes VM2 Spring Cloud Function vulnerabilities detection with FortiDevSec.
Multiple vulnerabilities such as CVE-2022-36067, CVE-2023-29017, CVE-2023-29199, CVE-2023-30547 have been reported in VM2. VM2 is a sandbox solution that can run untrusted code with whitelisted Node's built-in modules. By exploiting these flaws, threat actors can bypass the sandbox protections to gain remote code execution on the host running the sandbox. |
Scope | FortiDevSec SCA scanner updated in version 23.2.a |
Solution |
Detection against these vulnerabilities is empowered by the FortiDevSec Software Composition Analysis (SCA) scanner.
This technology enables FortiDevSec to assess with a high level of confidence if the application codebase is vulnerable to a specific vulnerability by identifying open-source software dependencies.
The SCA scanner is enabled by default. Once the scan is performed on an application, the result appears under the Software Composition Analysis tab.
A step-by-step guide on how to scan your application is available in the user guide.
For more details regarding mitigating the vulnerability by utilizing Fortinet products, refer to https://www.fortiguard.com/outbreak-alert/vm2-sandbox-escape. |