PT-2022-5323 · Nginx · Nginx Njs
Asuk4O
·
Published
2022-10-28
·
Updated
2024-08-03
·
CVE-2022-43285
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Nginx NJS version 0.7.4
Description
The issue is related to a buffer overflow in the njs promise reaction job function of the njs interpreter in the nginx server. This could allow a remote attacker to cause a denial of service. The vendor disputes the significance of this report, stating that NJS does not operate on untrusted input.
Recommendations
For Nginx NJS version 0.7.4, consider disabling the
njs promise reaction job function as a temporary workaround until a patch is available. Restrict access to the njs interpreter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nginx Njs