Segmentation Violation in Nginx NJS by Nginx
CVE-2022-29780

5.5MEDIUM

Key Information:

Vendor

Nginx

Status
Vendor
CVE Published:
2 June 2022

What is CVE-2022-29780?

A vulnerability in Nginx NJS version 0.7.2 was identified, resulting in a segmentation violation within the njs_array_prototype_sort function located in src/njs_array.c. This flaw could potentially disrupt the normal operation of applications utilizing Nginx NJS, making it essential for users and administrators to be aware of the issue and address it promptly.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.