CVE-2020-24348: Medium severity f5 njs vulnerability
Published Aug 13, 2020
·Updated
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njsjsonstringifyiterator in njsjson.c.
Affected Software
1 affected component
F5 Njs<=0.4.3
Remediation
Patch Available
Event History
Aug 13, 2020
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24348?
The severity of CVE-2020-24348 is medium with a CVSS score of 5.5.
2
What is the affected software for CVE-2020-24348?
The affected software for CVE-2020-24348 is F5 Njs with version up to and including 0.4.3.
3
What is the vulnerability description of CVE-2020-24348?
CVE-2020-24348 is a vulnerability in njs through 0.4.3, used in NGINX, which allows for an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
4
Are there any references for CVE-2020-24348?
Yes, you can find more information about CVE-2020-24348 at the following references: [Link 1](https://github.com/nginx/njs/issues/322) and [Link 2](https://security.netapp.com/advisory/ntap-20200918-0001/).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-24348?
The Common Weakness Enumeration (CWE) ID for CVE-2020-24348 is CWE-125.