CVE-2020-24347: Medium severity F5 Njs vulnerability
Published Aug 13, 2020
·Updated
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njslvlhshlevelfind in njslvlhsh.c.
Affected Software
3 affected componentsFixes available
F5 Njs<=0.4.3
Microsoft azl3 nginx 1.25.4-1
Microsoft azl3 nginx 1.25.4-4
Remediation
Patch Available
Event History
Aug 13, 2020
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
Description
Sep 4, 2025
Data Sourced
via Microsoft·02:57 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:57 AM
Affected Software
Updated
via Microsoft·02:57 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2020-24347?
CVE-2020-24347 is a vulnerability in njs, a JavaScript/ECMAScript engine for NGINX, which allows for an out-of-bounds read in njs_lvlhsh_level_find.
2
What is the severity of CVE-2020-24347?
The severity of CVE-2020-24347 is medium with a severity score of 5.5.
3
How does CVE-2020-24347 affect F5 Njs?
CVE-2020-24347 affects F5 Njs up to and including version 0.4.3.
4
How can CVE-2020-24347 be fixed?
To fix CVE-2020-24347, it is recommended to update to a version of njs that contains the fix, once it is released.
5
Where can I find more information about CVE-2020-24347?
You can find more information about CVE-2020-24347 on the GitHub issue page [link] and the NetApp advisory page [link].