CVE-2022-36127
Last modified
CVE-2022-36127 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.. EPSS estimates a 1.59% chance of exploitation in the next 30 days.
Description
A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Skywalking Nodejs Agent | < 0.5.1 |
References
- http://www.openwall.com/lists/oss-security/2022/07/18/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/x238wo4r5goy39dxdjcmlofp6gcdnqr3Mailing List, Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2022/07/18/1Mailing List, Third Party Advisory
- https://lists.apache.org/thread/x238wo4r5goy39dxdjcmlofp6gcdnqr3Mailing List, Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36127?
How severe is CVE-2022-36127?
How do I fix CVE-2022-36127?
Are you affected by CVE-2022-36127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
