CVE-2020-19695: Buffer Overflow
Published Apr 4, 2023
·Updated
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njsobjectproperty parameter of the njs/njsvm.c function.
Affected Software
3 affected components
Nginx njs<0.3.4
Nginx njs=2019-06-27
F5 Njs<0.3.4
Remediation
Patch Available
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-19695?
CVE-2020-19695 is a buffer overflow vulnerability found in Nginx NJS that allows a remote attacker to execute arbitrary code.
2
How does CVE-2020-19695 work?
CVE-2020-19695 works by exploiting a buffer overflow in the njs_object_property parameter of the njs/njs_vm.c function in Nginx NJS.
3
What software is affected by CVE-2020-19695?
The Nginx NJS software versions 0.3.4 and 2019-06-27 are affected by CVE-2020-19695.
4
How severe is CVE-2020-19695?
CVE-2020-19695 has a severity rating of 9.8 (Critical).
5
Is there a fix for CVE-2020-19695?
Yes, Nginx NJS released a fix for CVE-2020-19695. It is recommended to update to the latest version to mitigate the vulnerability.