Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NGINX njs 输入验证错误漏洞
Vulnerability Description
NGINX是美国NGINX公司的一款轻量级Web服务器/反向代理服务器及电子邮件(IMAP/POP3)代理服务器。njs是其中的一个支持扩展NGINX功能的脚本语言组件。 njs 0.4.3及之前版本(使用在NGINX)中的njs_value.c文件的njs_value_property存在安全漏洞。攻击者可利用该漏洞劫持控制流。
CVSS Information
N/A
Vulnerability Type
N/A