CVE-2022-29379: Critical severity f5 njs vulnerability
DISPUTED Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njsdefaultmoduleloader at /src/njs/src/njsmodule.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2, 0.7.3, or 0.7.4 release.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-29379?
CVE-2022-29379 is a vulnerability found in Nginx NJS v0.7.3 that allows for a stack overflow in the njs_default_module_loader function.
How severe is CVE-2022-29379?
CVE-2022-29379 has a severity rating of 9.8, which is classified as critical.
Which software versions are affected by CVE-2022-29379?
The Nginx NJS v0.7.3 version is affected by CVE-2022-29379.
Are there any fixes available for CVE-2022-29379?
Yes, there is a fix available for CVE-2022-29379. Please refer to the provided references for more information on the fix.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-29379?
CVE-2022-29379 is associated with CWE-787, which is a stack-based buffer overflow vulnerability.