ZeroHour

CVE-2021-22940

CVSS 3.1
7.5 high
EPSS
14%p96
Published
()
Modified
Description

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

Vendors
nodejsoraclenetappsiemensdebian
Products
node.js, graalvm, jd edwards enterpriseone tools, peoplesoft enterprise peopletools, nextgen api, sinec infrastructure network services, debian linux
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.