Vulnerability CVE-2021-22940: Information

Description

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Published: Aug. 16, 2021
Modified: Jan. 5, 2024
Error type identifier: CWE-416

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
      Start including
      12.0.0
      End excliding
      12.22.5

      cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
      Start including
      14.0.0
      End excliding
      14.17.5

      cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
      Start including
      16.0.0
      End excliding
      16.6.2

      Configuration 2

      cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:*

      cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:*

      cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
      End including
      9.2.6.1

      Configuration 3

      cpe:2.3:a:netapp:nextgen_api:-:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
      End excliding
      1.0.1.1

      Configuration 5

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*