
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-21524 affects all versions of the node-stringbuilder package, which was discovered in July 2024. The vulnerability is classified as an Out-of-bounds Read vulnerability due to incorrect memory length calculation when calling specific methods on a StringBuilder object with a non-empty string value input (Snyk Advisory, NVD).
The vulnerability occurs when calling ToBuffer, ToString, or CharAt methods on a StringBuilder object with a non-empty string value input. The issue stems from incorrect memory length calculation, which allows access to previously allocated memory through negative indexes. The vulnerability has received a CVSS v3.1 base score of 9.1 (Critical) from NVD and 8.2 (High) from Snyk, indicating its severe nature (NVD, GitHub POC).
The vulnerability can lead to Information Disclosure by allowing attackers to access previously allocated memory. This could potentially expose sensitive information that was previously stored in memory. The vulnerability requires no authentication and can be exploited remotely (Snyk Advisory).
A proof-of-concept exploit has been published demonstrating the vulnerability. The exploit involves calling the affected methods with negative indexes, which can result in accessing out-of-bounds memory locations. The vulnerability can be triggered through the ToBuffer, ToString, or CharAt methods (GitHub POC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."