Goahead Versions <= 6.0.0 Vulnerable to Use After Free and Double Free Vulnerabilities
CVE-2024-3187
What is CVE-2024-3187?
This vulnerability involves two specific issues classified as Use After Free (UAF) and one Double Free vulnerability within the Goahead web server framework. These vulnerabilities stem from Javascript template (JST) values not being cleared when they are freed during the parsing of JST templates. If the ME_GOAHEAD_JAVASCRIPT flag is activated, an attacker with the ability to modify JST files could exploit this flaw by uploading malicious templates. This can lead to memory corruption, resulting in potential Denial of Service conditions, with the possibility of code execution under particular circumstances.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GoAhead 0 <= 6.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
