PT-2022-5321 · Nginx · Nginx Njs

Q1Iq

·

Published

2022-10-28

·

Updated

2024-08-03

·

CVE-2022-43284

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Nginx NJS versions 0.7.2 through 0.7.4
Description The issue is related to a segmentation violation via the njs scope valid value function at njs scope.h. This could potentially allow a remote attacker to cause a denial of service. The vendor disputes the significance of this report, stating that NJS does not operate on untrusted input.
Recommendations For Nginx NJS versions 0.7.2 through 0.7.4, consider disabling the njs scope valid value function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2022-06626
CVE-2022-43284

Affected Products

Nginx Njs