CVE-2022-35173: High severity nginx njs vulnerability
Published Aug 18, 2022
·Updated
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
Affected Software
1 affected component
Nginx njs=0.7.5
Remediation
Patch Available
Event History
Aug 18, 2022
CVE Published
via MITRE·05:08 AM
Data Sourced
via MITRE·05:08 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-35173.
2
What is the severity of CVE-2022-35173?
The severity of CVE-2022-35173 is high with a CVSS score of 7.5.
3
What software is affected by CVE-2022-35173?
Nginx NJS version 0.7.5 is affected by CVE-2022-35173.
4
How can I fix the vulnerability in Nginx NJS?
To fix the vulnerability in Nginx NJS, you should update to a version that includes the patch for CVE-2022-35173.
5
Where can I find more information about CVE-2022-35173?
You can find more information about CVE-2022-35173 on the following references: [1](http://hg.nginx.org/njs/rev/b7c4e0f714a9), [2](https://github.com/nginx/njs/commit/404553896792b8f5f429dc8852d15784a59d8d3e), [3](https://github.com/nginx/njs/issues/553).