CVE-2021-33446: Null Pointer Dereference
Published Jul 26, 2022
·Updated
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjsnext() in mjs.c.
Affected Software
1 affected component
Cesanta mJS<2.20.0
Remediation
Patch Available
Event History
Jul 26, 2022
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33446?
CVE-2021-33446 is an issue discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6).
2
What is the severity of CVE-2021-33446?
The severity of CVE-2021-33446 is medium with a severity value of 5.5.
3
Which software is affected by CVE-2021-33446?
Cesanta MJS version up to 2.20.0 is affected by CVE-2021-33446.
4
What is the description of CVE-2021-33446?
CVE-2021-33446 is a vulnerability in mjs where there is a NULL pointer dereference in mjs_next() in mjs.c.
5
How can I fix CVE-2021-33446?
Upgrade Cesanta MJS to a version higher than 2.20.0 to fix CVE-2021-33446.