CVE-2021-22930

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
07/10/2021
Last modified:
05/01/2024

Description

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 12.0.0 (including) 12.22.4 (excluding)
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* 14.0.0 (including) 14.17.4 (excluding)
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 16.0.0 (including) 16.6.0 (excluding)
cpe:2.3:a:netapp:nextgen_api:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* 1.0.1.1 (excluding)
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*