CVE-2021-44533
⚪ Do wiadomości
Błąd w Node.js umożliwia atakującym obejście weryfikacji certyfikatów.
CVSS
5.3
EPSS
9.4%
Exploit
poc
Vendor
oracle
Opis źródłowy (NVD)
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 9.4% |
| Opublikowano (NVD) | 2022-02-24 19:15:09 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:13 UTC |
Referencje
- https://hackerone.com/reports/1429694 ([email protected]) [Exploit, Mitigation, Third Party Advisory]
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ ([email protected]) [Release Notes, Vendor Advisory]
- https://security.netapp.com/advisory/ntap-20220325-0007/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2022/dsa-5170 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html ([email protected]) [Third Party Advisory]