CVE-2020-13110Uncontrolled Search Path Element in Project Kerberos

Severity
7.8HIGHNVD
EPSS
0.1%
top 79.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateJul 13

Description

The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

npmmit/kerberos< 1.0.0

🔴Vulnerability Details

3
OSV
DLL Injection in kerberos2020-09-04
GHSA
DLL Injection in kerberos2020-09-04
CVEList
CVE-2020-13110: The kerberos package before 12020-05-16

📋Vendor Advisories

1
Red Hat
exiv2: integer buffer overflow in getUShort fucntion leads to DoS2021-07-13
CVE-2020-13110 — Uncontrolled Search Path Element | cvebase