First published: Sun Dec 26 2021(Updated: )
An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Tremor-script | >=0.7.2<0.11.6 | |
>=0.7.2<0.11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-45702 is classified as medium due to the potential for a use-after-free vulnerability.
To fix CVE-2021-45702, update the tremor-script crate to version 0.11.6 or later.
CVE-2021-45702 affects versions of the tremor-script crate from 0.7.2 to 0.11.6.
CVE-2021-45702 is a use-after-free vulnerability resulting from improper handling during merge operations.
The maintainers of the tremor-script crate are responsible for addressing CVE-2021-45702.