ID

VAR-202210-2112


CVE

CVE-2022-43286


TITLE

Nginx Resource Management Error Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202210-2498

DESCRIPTION

Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c

Trust: 0.99

sources: NVD: CVE-2022-43286 // VULHUB: VHN-440261

AFFECTED PRODUCTS

vendor:f5model:njsscope:eqversion:0.7.2

Trust: 1.0

sources: NVD: CVE-2022-43286

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2022-43286
value: CRITICAL

Trust: 1.0

CNNVD: CNNVD-202210-2498
value: CRITICAL

Trust: 0.6

NVD:
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2022-43286 // CNNVD: CNNVD-202210-2498

PROBLEMTYPE DATA

problemtype:CWE-416

Trust: 1.1

sources: VULHUB: VHN-440261 // NVD: CVE-2022-43286

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202210-2498

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-202210-2498

CONFIGURATIONS

sources: NVD: CVE-2022-43286

PATCH

title:Nginx Remediation of resource management error vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqbyid.tag?id=212578

Trust: 0.6

sources: CNNVD: CNNVD-202210-2498

EXTERNAL IDS

db:NVDid:CVE-2022-43286

Trust: 1.7

db:CNNVDid:CNNVD-202210-2498

Trust: 0.6

db:VULHUBid:VHN-440261

Trust: 0.1

sources: VULHUB: VHN-440261 // NVD: CVE-2022-43286 // CNNVD: CNNVD-202210-2498

REFERENCES

url:https://github.com/nginx/njs/commit/2ad0ea24a58d570634e09c2e58c3b314505eaa6a

Trust: 1.7

url:https://github.com/nginx/njs/issues/480

Trust: 1.7

url:https://cxsecurity.com/cveshow/cve-2022-43286/

Trust: 0.6

sources: VULHUB: VHN-440261 // NVD: CVE-2022-43286 // CNNVD: CNNVD-202210-2498

SOURCES

db:VULHUBid:VHN-440261
db:NVDid:CVE-2022-43286
db:CNNVDid:CNNVD-202210-2498

LAST UPDATE DATE

2023-12-18T11:55:26.557000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-440261date:2022-10-31T00:00:00
db:NVDid:CVE-2022-43286date:2022-10-31T17:48:08.333
db:CNNVDid:CNNVD-202210-2498date:2022-11-01T00:00:00

SOURCES RELEASE DATE

db:VULHUBid:VHN-440261date:2022-10-28T00:00:00
db:NVDid:CVE-2022-43286date:2022-10-28T21:15:10.213
db:CNNVDid:CNNVD-202210-2498date:2022-10-28T00:00:00