Nginx NJS Vulnerability in Version 0.7.10
CVE-2023-27729
7.5HIGH
Summary
A vulnerability has been identified in Nginx NJS version 0.7.10, related to an illegal memcpy operation within the njs_vmcode_return function located in src/njs_vmcode.c. This flaw can have serious implications on data handling, potentially leading to unexpected behavior or unauthorized access. Immediate attention to this issue is suggested for users of the affected version to prevent exploitation.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved