CVE-2021-46461: Buffer Overflow
njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njsvmcodetypeof in /src/njsvmcode.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-46461?
CVE-2021-46461 is a vulnerability in njs, a JavaScript/ECMAScript engine used by NGINX, that allows an attacker to trigger an out-of-bounds array access.
What is the severity of CVE-2021-46461?
CVE-2021-46461 has a severity rating of 9.8 (Critical).
Which software is affected by CVE-2021-46461?
Nginx NJS versions up to and including 0.7.0 are affected by CVE-2021-46461.
How can I fix CVE-2021-46461?
To fix CVE-2021-46461, upgrade to a version of Nginx NJS that is higher than 0.7.0.
Where can I find more information about CVE-2021-46461?
You can find more information about CVE-2021-46461 at the following references: [link1](https://github.com/nginx/njs/commit/d457c9545e7e71ebb5c0479eb16b9d33175855e2), [link2](https://github.com/nginx/njs/issues/450), [link3](https://security.netapp.com/advisory/ntap-20220303-0007/).