First published: Tue Apr 04 2023(Updated: )
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nginx NJS | <0.3.4 | |
Nginx NJS | =2019-06-27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19695 is a buffer overflow vulnerability found in Nginx NJS that allows a remote attacker to execute arbitrary code.
CVE-2020-19695 works by exploiting a buffer overflow in the njs_object_property parameter of the njs/njs_vm.c function in Nginx NJS.
The Nginx NJS software versions 0.3.4 and 2019-06-27 are affected by CVE-2020-19695.
CVE-2020-19695 has a severity rating of 9.8 (Critical).
Yes, Nginx NJS released a fix for CVE-2020-19695. It is recommended to update to the latest version to mitigate the vulnerability.