CVE-2022-34029: Critical severity f5 njs vulnerability
Published Jul 18, 2022
·Updated
Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njsscopevalue at njsscope.h.
Affected Software
1 affected component
F5 Njs=0.7.4
Remediation
Patch Available
Event History
Jul 18, 2022
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
Description
Frequently Asked Questions
1
What is CVE-2022-34029?
CVE-2022-34029 refers to a vulnerability in Nginx NJS v0.7.4 that allows an out-of-bounds read via njs_scope_value at njs_scope.h.
2
What software versions are affected by CVE-2022-34029?
CVE-2022-34029 affects Nginx NJS v0.7.4.
3
How severe is CVE-2022-34029?
CVE-2022-34029 is considered critical with a severity rating of 9.1.
4
How can I fix CVE-2022-34029?
To fix CVE-2022-34029, update Nginx NJS to a version that does not contain this vulnerability.
5
Where can I find more information about CVE-2022-34029?
More information about CVE-2022-34029 can be found at the following link: [https://github.com/nginx/njs/issues/506](https://github.com/nginx/njs/issues/506)