CVE-2020-24346: Use After Free
njs through 0.4.3, used in NGINX, has a use-after-free in njsjsonparseiteratorcall in njsjson.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-24346?
CVE-2020-24346 is a vulnerability found in njs through 0.4.3 used in NGINX, which can lead to a use-after-free issue in njs_json_parse_iterator_call function in njs_json.c.
How severe is CVE-2020-24346?
CVE-2020-24346 has a severity score of 7.8, which is considered high.
Which software is affected by CVE-2020-24346?
The affected software is F5 Njs with versions up to and including 0.4.3 when used in NGINX.
How can I fix CVE-2020-24346?
To fix CVE-2020-24346, users are advised to update to a version of njs that is later than 0.4.3, once a patch or update is released.
Where can I find more information about CVE-2020-24346?
You can find more information about CVE-2020-24346 at the following references: - [GitHub issue](https://github.com/nginx/njs/issues/325) - [NetApp advisory](https://security.netapp.com/advisory/ntap-20200918-0001/)