CVE-2022-43285: High severity F5 Njs vulnerability
Published Oct 28, 2022
·Updated
DISPUTED Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njspromisereactionjob. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input.
Affected Software
1 affected component
F5 Njs=0.7.4
Remediation
Patch Available
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Disputed
09:15 PM
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-43285?
CVE-2022-43285 is a vulnerability in Nginx NJS v0.7.4 that leads to a segmentation violation in njs_promise_reaction_job.
2
Is CVE-2022-43285 a high severity vulnerability?
Yes, CVE-2022-43285 has a severity value of 7.5, which is considered high.
3
What software is affected by CVE-2022-43285?
F5 Njs version 0.7.4 is affected by CVE-2022-43285.
4
Why does the vendor dispute the significance of CVE-2022-43285?
The vendor disputes the significance of this report because NJS does not operate on untrusted input.
5
Where can I find more information about CVE-2022-43285?
You can find more information about CVE-2022-43285 at the following link: [https://github.com/nginx/njs/issues/533](https://github.com/nginx/njs/issues/533).