Skip to content

@fastly/js-compute has a use-after-free in some host call implementations

Moderate severity GitHub Reviewed Published Jun 26, 2024 in fastly/js-compute-runtime • Updated Jun 26, 2024

Package

npm @fastly/js-compute (npm)

Affected versions

>= 3.0.0, < 3.16.0

Patched versions

3.16.0

Description

Impact

The implementation of the following functions were determined to include a use-after-free bug:

  • FetchEvent.client.tlsCipherOpensslName
  • FetchEvent.client.tlsProtocol
  • FetchEvent.client.tlsClientCertificate
  • FetchEvent.client.tlsJA3MD5
  • FetchEvent.client.tlsClientHello
  • CacheEntry.prototype.userMetadata of the fastly:cache subsystem
  • Device.lookup of the fastly:device subsystem

This bug could allow for an unintended data leak if the result of the preceding functions were sent anywhere else, and often results in a Compute service crash causing an HTTP 500 error to be returned. As all requests to Compute are isolated from one another, the only data at risk is data present for a single request.

Patches

This bug has been fixed in version 3.16.0 of the @fastly/js-compute package.

Workarounds

There are no workarounds for this bug, any use of the affected functions introduces the possibility of a data leak or crash in guest code.

References

@elliottt elliottt published to fastly/js-compute-runtime Jun 26, 2024
Published to the GitHub Advisory Database Jun 26, 2024
Reviewed Jun 26, 2024
Published by the National Vulnerability Database Jun 26, 2024
Last updated Jun 26, 2024

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H

Weaknesses

CVE ID

CVE-2024-38375

GHSA ID

GHSA-mp3g-vpm9-9vqv

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.