F5
F5 NJS: vulnerabilidades y CVE
F5 NJS tiene 40 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 15 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses1
Críticas15
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8711 | Crítica (9.2) | 0.79% | — | 19 may 2026 | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch()… |
| CVE-2023-27730 | Alta (7.5) | 0.74% | — | 9 abr 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. |
| CVE-2023-27729 | Alta (7.5) | 0.66% | — | 9 abr 2023 | Nginx NJS v0.7.10 was discovered to contain an illegal memcpy via the function njs_vmcode_return at src/njs_vmcode.c. |
| CVE-2023-27728 | Alta (7.5) | 0.74% | — | 9 abr 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. |
| CVE-2023-27727 | Alta (7.5) | 0.73% | — | 9 abr 2023 | Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. |
| CVE-2020-19695 | Crítica (9.8) | 1.3% | — | 4 abr 2023 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function. |
| CVE-2020-19692 | Crítica (9.8) | 1.3% | — | 4 abr 2023 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file. |
| CVE-2022-43286 | Crítica (9.8) | 0.96% | — | 28 oct 2022 | Nginx NJS v0.7.2 was discovered to contain a heap-use-after-free bug caused by illegal memory copy in the function njs_json_parse_iterator_call at njs_json.c. |
| CVE-2022-43285 | Alta (7.5) | 0.78% | — | 28 oct 2022 | Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. |
| CVE-2022-43284 | Alta (7.5) | 0.85% | — | 28 oct 2022 | Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted… |
| CVE-2022-38890 | Media (5.5) | 0.30% | — | 15 sept 2022 | Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h |
| CVE-2022-34032 | Alta (7.5) | 0.89% | — | 18 jul 2022 | Nginx NJS v0.7.5 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c. |
| CVE-2022-34031 | Alta (7.5) | 0.89% | — | 18 jul 2022 | Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_value_to_number at src/njs_value_conversion.h. |
| CVE-2022-34030 | Alta (7.5) | 0.89% | — | 18 jul 2022 | Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_djb_hash at src/njs_djb_hash.c. |
| CVE-2022-34029 | Crítica (9.1) | 1.2% | — | 18 jul 2022 | Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h. |
| CVE-2022-34028 | Alta (7.5) | 1.0% | — | 18 jul 2022 | Nginx NJS v0.7.5 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h. |
| CVE-2022-34027 | Alta (7.5) | 0.89% | — | 18 jul 2022 | Nginx NJS v0.7.4 was discovered to contain a segmentation violation via njs_value_property at njs_value.c. |
| CVE-2022-32414 | Media (5.5) | 0.66% | — | 21 jun 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c. |
| CVE-2022-31307 | Media (5.5) | 0.66% | — | 21 jun 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c. |
| CVE-2022-31306 | Media (5.5) | 0.66% | — | 21 jun 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. |
| CVE-2022-29379 | Crítica (9.8) | 1.8% | — | 25 may 2022 | Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in… |
| CVE-2022-29369 | Alta (7.5) | 1.2% | — | 12 may 2022 | Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. |
| CVE-2022-28049 | Media (5.5) | 0.82% | — | 15 abr 2022 | NGINX NJS 0.7.2 was discovered to contain a NULL pointer dereference via the component njs_vmcode_array at /src/njs_vmcode.c. |
| CVE-2022-27008 | Alta (7.5) | 1.7% | — | 14 abr 2022 | nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. |
| CVE-2022-27007 | Crítica (9.8) | 1.6% | — | 14 abr 2022 | nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). |
| CVE-2022-25139 | Crítica (9.8) | 1.6% | — | 14 feb 2022 | njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. |
| CVE-2021-46463 | Crítica (9.8) | 1.7% | — | 14 feb 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then(). |
| CVE-2021-46462 | Alta (7.5) | 1.7% | — | 14 feb 2022 | njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c. |
| CVE-2020-24349 | Media (5.5) | 0.53% | — | 13 ago 2020 | njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface. |
| CVE-2020-24348 | Media (5.5) | 0.42% | — | 13 ago 2020 | njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de F5
Big-ip Access Policy Manager · 630Big-ip Application Security Manager · 581Big-ip Advanced Firewall Manager · 552Big-ip Local Traffic Manager · 541Big-ip Policy Enforcement Manager · 533Big-ip Link Controller · 525Big-ip Application Acceleration Manager · 524Big-ip Analytics · 511Big-ip Global Traffic Manager · 490Big-ip Domain Name System · 469Big-ip Fraud Protection Service · 405Big-ip Webaccelerator · 297