CVE-2024-35384: Input Validation
Published May 21, 2024
·Updated
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsarraylength function in the mjs.c file.
Affected Software
2 affected components
Cesanta mJS
Cesanta mJS=2.20.0
Event History
May 21, 2024
CVE Published
via MITRE·01:38 PM
Data Sourced
via MITRE·01:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35384?
CVE-2024-35384 has been rated as a denial of service vulnerability, which can disrupt the service for users.
2
How can I fix CVE-2024-35384?
To fix CVE-2024-35384, upgrade to a patched version of Cesanta mjs that addresses the issue in the mjs_array_length function.
3
What versions of Cesanta mjs are affected by CVE-2024-35384?
CVE-2024-35384 affects Cesanta mjs version 2.20.0.
4
How does CVE-2024-35384 affect my application?
CVE-2024-35384 can allow remote attackers to exploit the mjs_array_length function, potentially leading to service disruption.
5
Is there a known workaround for CVE-2024-35384?
Currently, there are no known workarounds for CVE-2024-35384; the recommended action is to update to a secure version.