📦 Njs

by F5

🔍 What is Njs?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-34029

CRITICAL CVSS 9.1 Jul 18, 2022

CVE-2022-34029 is an out-of-bounds read vulnerability in Nginx NJS (JavaScript engine) that could allow attackers to read sensitive memory contents or cause denial of service. This affects systems run...

CVE-2022-29379

CRITICAL CVSS 9.8 May 25, 2022

This CVE describes a stack overflow vulnerability in Nginx NJS module loader that could allow remote code execution or denial of service. However, multiple sources dispute this affects released versio...

CVE-2021-46463

CRITICAL CVSS 9.8 Feb 14, 2022

CVE-2021-46463 is a critical type confusion vulnerability in njs (NGINX JavaScript) that allows attackers to hijack control flow and potentially execute arbitrary code. It affects NGINX servers using ...

CVE-2023-27728

HIGH CVSS 7.5 Apr 9, 2023

This vulnerability in Nginx NJS v0.7.10 allows attackers to trigger a segmentation violation via the njs_dump_is_recursive function, potentially causing denial of service or arbitrary code execution. ...

CVE-2023-27730

HIGH CVSS 7.5 Apr 9, 2023

CVE-2023-27730 is a memory corruption vulnerability in Nginx NJS JavaScript engine that can cause segmentation faults via the njs_lvlhsh_find function. This affects systems running Nginx with NJS modu...

CVE-2022-34028

HIGH CVSS 7.5 Jul 18, 2022

CVE-2022-34028 is a segmentation fault vulnerability in Nginx NJS JavaScript engine that occurs when processing malformed UTF-8 sequences. This vulnerability could allow attackers to crash Nginx proce...

CVE-2022-34031

HIGH CVSS 7.5 Jul 18, 2022

CVE-2022-34031 is a segmentation violation vulnerability in Nginx NJS JavaScript engine that could allow attackers to crash the Nginx process or potentially execute arbitrary code. This affects system...

CVE-2022-29369

HIGH CVSS 7.5 May 12, 2022

CVE-2022-29369 is a segmentation fault vulnerability in Nginx NJS (JavaScript engine) that can cause denial of service or potentially allow arbitrary code execution. It affects systems running Nginx w...

CVE-2021-46462

HIGH CVSS 7.5 Feb 14, 2022

CVE-2021-46462 is a segmentation fault vulnerability in njs (NGINX JavaScript) through version 0.7.1. This vulnerability could allow an attacker to crash NGINX processes via specially crafted JavaScri...