First published: Mon Feb 14 2022(Updated: )
njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 Njs | <=0.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-46463.
The affected software is njs through version 0.7.1 used in NGINX.
The severity of CVE-2021-46463 is critical with a CVSS score of 9.8.
CVE-2021-46463 exploits a Type Confusion vulnerability in njs_promise_perform_then() leading to a control flow hijack.
Yes, a fix for CVE-2021-46463 is available. It is recommended to update njs to version 0.7.2 or later.