GHSA-4mq4-7rw3-vm5j
Wasmer filesystem sandbox not enforced
Details
### Summary As of Wasmer version v4.2.3, Wasm programs can access the filesystem outside of the sandbox.
### Details https://github.com/wasmerio/wasmer/issues/4267
### PoC A minimal Rust program:
``` fn main() { let f = std::fs::OpenOptions::new() .write(true) .create_new(true) .open("abc") .unwrap(); } ```
This should be compiled with `cargo build --target wasm32-wasi`. The compiled program, when run with wasmer WITHOUT `--dir`, can still create a file in the working directory.
### Impact Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host filesystem.
Are you affected?
Enter the version of the package you're using.
Affected packages
3.0.0Fixed in: 4.2.4Upgrade wasmer-cli to 4.2.4 or newer (ecosystem crates.io).
References
- https://github.com/wasmerio/wasmer/security/advisories/GHSA-4mq4-7rw3-vm5j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-51661[ADVISORY]
- https://github.com/wasmerio/wasmer/issues/4267[WEB]
- https://github.com/wasmerio/wasmer/commit/4d63febf9d8b257b0531963b85df48d45d0dbf3c[WEB]
- https://github.com/wasmerio/wasmer/commit/e3923612c23123025c26f982d390e34df7df030f[WEB]
- https://github.com/wasmerio/wasmer[PACKAGE]