CVE-2021-46463: Critical severity f5 njs vulnerability
Published Feb 14, 2022
·Updated
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njspromiseperformthen().
Affected Software
1 affected component
F5 Njs<=0.7.1
Remediation
Patch Available
Event History
Feb 14, 2022
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-46463.
2
What is the affected software?
The affected software is njs through version 0.7.1 used in NGINX.
3
What is the severity of CVE-2021-46463?
The severity of CVE-2021-46463 is critical with a CVSS score of 9.8.
4
How does CVE-2021-46463 exploit the vulnerability?
CVE-2021-46463 exploits a Type Confusion vulnerability in njs_promise_perform_then() leading to a control flow hijack.
5
Is there a fix available for CVE-2021-46463?
Yes, a fix for CVE-2021-46463 is available. It is recommended to update njs to version 0.7.2 or later.