First published: Mon Feb 14 2022(Updated: )
njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nginx NJS | <=0.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46461 is a vulnerability in njs, a JavaScript/ECMAScript engine used by NGINX, that allows an attacker to trigger an out-of-bounds array access.
CVE-2021-46461 has a severity rating of 9.8 (Critical).
Nginx NJS versions up to and including 0.7.0 are affected by CVE-2021-46461.
To fix CVE-2021-46461, upgrade to a version of Nginx NJS that is higher than 0.7.0.
You can find more information about CVE-2021-46461 at the following references: [link1](https://github.com/nginx/njs/commit/d457c9545e7e71ebb5c0479eb16b9d33175855e2), [link2](https://github.com/nginx/njs/issues/450), [link3](https://security.netapp.com/advisory/ntap-20220303-0007/).