Heap-Use-After-Free Vulnerability in Nginx NJS Product
CVE-2022-43286
9.8CRITICAL
Summary
A vulnerability present in Nginx NJS v0.7.2 is due to a heap-use-after-free error, which arises from an illegal memory copy operation in the function njs_json_parse_iterator_call located in njs_json.c. This flaw can potentially allow attackers to exploit memory mismanagement and lead to unintended behaviors, affecting application stability and security.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved