ZeroHour

CVE-2021-22930

CVSS 3.1
9.8 critical
EPSS
36%p98
Published
()
Modified
Description

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

Vendors
nodejsnetappsiemensdebian
Products
node.js, nextgen api, sinec infrastructure network services, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.