Back to directory
WRITEUP #1939

Remote Code Execution in Spotify’s Backstage via vm2 Sandbox Escape (CVSS Score of 9.8)

RCEVM sandbox escape
by@G4lGo89(Gal Goldsthein)
Program
Spotify
Published
Nov 15, 2022
Added to HackDex
Nov 21, 2022
Read Full Writeuphttps://www.oxeye.io/blog/remote-code-execution-in-spotifys-backstage
RELATED WRITEUPS
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
RCETLD hacking

Built with ❤️ by Shubham Rawat