← Back

CVE-2021-44532

nvd nist
Published: Feb 24, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.

Affected (16)

1 product
Node.js
7 products
Graalvm
Mysql Cluster
Mysql Connectors
Mysql Enterprise Monitor
Mysql Server
Mysql Workbench
Peoplesoft Enterprise Peopletools
1 product
Debian Linux
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
Before 12.22.9
From 14.0.0 to 14.18.3
From 16.0.0 to 16.13.2
From 17.0.0 to 17.3.1
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 20.3.5
Version 21.3.1
Version 22.0.0.2
Up to 8.0.29
Up to 8.0.28
Up to 8.0.29
Oracle
Up to 5.7.37
From 8.0.0 to 8.0.28
From 8.0.0 to 8.0.28
Oracle
Version 8.58
Version 8.59
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (12)

Source: support@hackerone.com
MitigationThird Party Advisory
Source: support@hackerone.com
ExploitRelease NotesVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitRelease NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.