CVE-2021-33447: Null Pointer Dereference
Published Jul 26, 2022
·Updated
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is NULL pointer dereference in mjsprint() in mjs.c.
Affected Software
1 affected component
Cesanta mJS<2.20.0
Remediation
Patch Available
Event History
Jul 26, 2022
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33447?
CVE-2021-33447 is a vulnerability in the mjs (mJS: Restricted JavaScript engine) ES6 (JavaScript version 6) that allows for a NULL pointer dereference in mjs_print() in mjs.c.
2
What is the severity of CVE-2021-33447?
The severity of CVE-2021-33447 is medium, with a severity value of 5.5.
3
What software is affected by CVE-2021-33447?
Cesanta MJS version up to exclusive 2.20.0 is affected by CVE-2021-33447.
4
How can I fix CVE-2021-33447?
Upgrade to a version of Cesanta MJS that is higher than 2.20.0, as the vulnerability has been fixed in later versions.
5
Where can I find more information about CVE-2021-33447?
You can find more information about CVE-2021-33447 on the GitHub page for Cesanta MJS and in the provided references.