PT-2020-15700 · Nginx · Njs

Changocheno

·

Published

2020-08-13

·

Updated

2022-10-05

·

CVE-2020-24349

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions njs versions prior to 0.4.4
Description The issue allows for control-flow hijack in the njs value property function within njs value.c. It is noted that the vendor considers this issue to be of minimal concern in the NGINX use case due to the lack of a remote attack surface.
Recommendations For versions prior to 0.4.4, update to version 0.4.4 or later to resolve the issue.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2020-24349

Affected Products

Njs