First published: Mon Feb 14 2022(Updated: )
njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Njs | <0.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-25139.
The severity of CVE-2022-25139 is critical with a severity value of 9.8.
The affected software for CVE-2022-25139 is F5 Njs up to version 0.7.2.
CVE-2022-25139 is a heap use-after-free vulnerability in njs_await_fulfilled in njs through 0.7.0.
To fix CVE-2022-25139, you should apply the latest security patch or upgrade to a fixed version when available.