CVE-2022-27007: Use After Free
Published Apr 14, 2022
·Updated
nginx njs 0.7.2 is affected suffers from Use-after-free in njsfunctionframealloc() when it try to invoke from a restored frame saved with njsfunctionframesave().
Affected Software
1 affected component
F5 Njs=0.7.2
Remediation
Patch Available
Event History
Apr 14, 2022
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-27007.
2
What is the severity of CVE-2022-27007?
The severity of CVE-2022-27007 is critical (9.8).
3
Which software is affected by this vulnerability?
The F5 Njs software version 0.7.2 is affected by this vulnerability.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-416.
5
How can I fix CVE-2022-27007?
There is no known fix or patch available for CVE-2022-27007 at the moment. It is recommended to monitor the vendor's website and apply any updates or patches as soon as they are available.