CVE-2020-24349: Use After Free
Published Aug 13, 2020
·Updated
njs through 0.4.3, used in NGINX, allows control-flow hijack in njsvalueproperty in njsvalue.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
Affected Software
1 affected component
F5 Njs<=0.4.3
Remediation
Patch Available
Event History
Aug 13, 2020
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24349?
CVE-2020-24349 is a vulnerability in njs, specifically in the njs_value_property function in njs_value.c.
2
What is the severity of CVE-2020-24349?
CVE-2020-24349 has a severity rating of medium, with a severity value of 5.5.
3
How does CVE-2020-24349 affect NGINX?
CVE-2020-24349 affects NGINX as it uses the vulnerable version of njs (0.4.3).
4
What is the vendor's view on the severity of CVE-2020-24349 for NGINX?
The vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
5
How can I fix CVE-2020-24349?
To fix CVE-2020-24349, update to a version of njs that is not affected by the vulnerability.