Denial of Service Vulnerability in Cesanta MJS v2.20.0
CVE-2023-29570

5.5MEDIUM

Key Information:

Vendor

Cesanta

Status
Vendor
CVE Published:
24 April 2023

What is CVE-2023-29570?

A vulnerability exists in Cesanta MJS v2.20.0 that can be exploited to trigger a segmentation fault, leading to an unexpected termination of the service. This Denial of Service (DoS) flaw, located in the mjs_ffi_cb_free function within the source code, can interrupt the normal operation of applications relying on MJS, making it critical for users to apply security measures to mitigate potential disruptions.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.