CVE-2022-28049: Null Pointer Dereference
Published Apr 15, 2022
·Updated
NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njsvmcodearray at /src/njsvmcode.c.
Affected Software
1 affected component
F5 Njs=0.7.2
Remediation
Event History
Apr 15, 2022
CVE Published
via MITRE·01:06 PM
Data Sourced
via MITRE·01:06 PM
Description
Frequently Asked Questions
1
What is CVE-2022-28049?
CVE-2022-28049 is a vulnerability in NGINX NJS 0.7.2 that allows for a NULL pointer dereference via the component njs_vmcode_array.
2
How severe is CVE-2022-28049?
CVE-2022-28049 has a severity rating of 5.5 (medium).
3
Which software versions are affected by CVE-2022-28049?
CVE-2022-28049 affects F5 Njs version 0.7.2.
4
How can I fix CVE-2022-28049?
To fix CVE-2022-28049, upgrade NGINX NJS to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-28049?
You can find more information about CVE-2022-28049 at the following references: [link1], [link2], [link3].