CVE-2022-34031: High severity f5 njs vulnerability
Published Jul 18, 2022
·Updated
Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njsvaluetonumber at src/njsvalueconversion.h.
Affected Software
1 affected component
F5 Njs=0.7.5
Event History
Jul 18, 2022
CVE Published
via MITRE·08:14 PM
Data Sourced
via MITRE·08:14 PM
Description
Frequently Asked Questions
1
What is CVE-2022-34031?
CVE-2022-34031 is a vulnerability in Nginx NJS v0.7.5 that allows for a segmentation violation via njs_value_to_number at src/njs_value_conversion.h.
2
How severe is CVE-2022-34031?
CVE-2022-34031 is classified as a high severity vulnerability with a severity score of 7.5.
3
Which software versions are affected by CVE-2022-34031?
The affected software version is Nginx NJS v0.7.5.
4
How can I fix CVE-2022-34031?
To fix CVE-2022-34031, consider upgrading to a version of Nginx NJS that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-34031?
You can find more information about CVE-2022-34031 at the following reference: https://github.com/nginx/njs/issues/523