Alpine: multiple nginx packages: security update to 1.20.2-r2

medium Tenable Self-Hosted Container Security Plugin ID 424212

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via
njs_vmcode_typeof in /src/njs_vmcode.c. (CVE-2021-46461)

- njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via
njs_object_set_prototype in /src/njs_object.c. (CVE-2021-46462)

- njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type
Confusion vulnerability in njs_promise_perform_then(). (CVE-2021-46463)

- njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
(CVE-2022-25139)

- The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation
can reset many streams quickly, as exploited in the wild in August through October 2023. (CVE-2023-44487)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-46461

https://security.alpinelinux.org/vuln/CVE-2021-46462

https://security.alpinelinux.org/vuln/CVE-2021-46463

https://security.alpinelinux.org/vuln/CVE-2022-25139

https://security.alpinelinux.org/vuln/CVE-2023-44487

Plugin Details

Severity: Medium

ID: 424212

Version: Revision 1.15

Type: Local

Published: 4/4/2025

Updated: 6/26/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 97.35

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-25139

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 6.9

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2023-44487

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2/14/2022

CISA Known Exploited Vulnerability Due Dates: 10/31/2023

Reference Information

CVE: CVE-2021-46461, CVE-2021-46462, CVE-2021-46463, CVE-2022-25139, CVE-2023-44487

IAVA: 2023-A-0537-S