← Back

CVE-2021-44533

nvd nist
Published: Feb 24, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.

Affected (17)

1 product
Node.js
7 products
Graalvm
Mysql Cluster
Mysql Connectors
Mysql Enterprise Monitor
Mysql Server
Mysql Workbench
Peoplesoft Enterprise Peopletools
1 product
Debian Linux
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Nodejs
Before 12.22.9
From 14.0.0 to 14.18.3
From 16.0.0 to 16.13.2
From 17.0.0 to 17.3.1
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 20.3.5
Version 21.3.1
Version 22.0.0.2
Oracle
Before 8.0.29
Version 8.0.29
Up to 8.0.28
Up to 8.0.29
Oracle
Up to 5.7.37
From 8.0.0 to 8.0.28
Up to 8.0.28
Oracle
Version 8.58
Version 8.59
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (12)

Source: support@hackerone.com
ExploitMitigationThird Party Advisory
Source: support@hackerone.com
Release NotesVendor Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: support@hackerone.com
PatchThird Party Advisory
Source: support@hackerone.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.