← Back

CVE-2021-44531

nvd nist
Published: Feb 24, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD

Description

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

Affected (15)

1 product
Node.js
7 products
Graalvm
Mysql Connectors
Mysql Enterprise Monitor
Mysql Server
Mysql Workbench
Peoplesoft Enterprise Peopletools
Mysql Cluster
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
Before 12.22.9
From 14.0.0 to 14.18.3
From 16.0.0 to 16.13.2
From 17.0.0 to 17.3.1
Configuration B
10 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 20.3.5
Version 21.3.1
Version 22.0.0.2
Up to 8.0.28
Up to 8.0.29
Oracle
Up to 5.7.37
From 8.0.0 to 8.0.28
Up to 8.0.28
Oracle
Version 8.58
Version 8.59
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 8.0.29

References (12)

Source: support@hackerone.com
Issue TrackingMitigationPatchThird Party Advisory
Source: support@hackerone.com
Release NotesVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.