Junglewise Threat Intelligence

CVE-2024-38375: Fastly js-compute use-after-free in host call implementations

CVE-2024-38375 · Severity: low · CVSS 3.1 · Published 2024-06-26

Vendors: npm.

Executive brief

Fastly's js-compute runtime library, used to build and run serverless computing applications, contains a use-after-free memory bug in several TLS certificate and cache query functions. An attacker with elevated privileges who can interact with these specific functions may cause the service to crash (returning HTTP 500 errors) or potentially leak sensitive data from a single request, such as TLS cipher names or client certificate information.

Technical details

The vulnerability is a use-after-free (CWE-416) bug in host call implementations affecting multiple functions: FetchEvent.client.tlsCipherOpensslName, FetchEvent.client.tlsProtocol, FetchEvent.client.tlsClientCertificate, FetchEvent.client.tlsJA3MD5, FetchEvent.client.tlsClientHello, CacheEntry.prototype.userMetadata, and Device.lookup. The attack requires network access, high privileges, and user interaction. Exploitation can result in unintended data leaks or Compute service crashes returning HTTP 500 errors; as requests are isolated, only single-request data is at risk. The vulnerability affects @fastly/js-compute versions 3.0.0 through 3.15.x, with a fix released in version 3.16.0.

Affected products

  • Fastly js-compute 3.0.0 to 3.15.x

Timeline

  • 2024-06-26: disclosed
  • 2024-06-26: patched: Fixed in version 3.16.0

References

Related threats