CVE-2020-8174
published 2020-07-24CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
PriorityP347high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
7.65%
93.9th percentile
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 10.21.0~dfsg-1 (bookworm) | nodejs 10.21.0~dfsg-1 (bookworm) |
| https | github.com_nodejs_node | — | — |
| msrc | cm1_nodejs_14.17.2-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node.js | < 10.21.0 | 10.21.0 |
| nodejs | node.js | >= 12.0.0 < 12.18.0 | 12.18.0 |
| nodejs | node.js | >= 14.0.0 < 14.4.0 | 14.4.0 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.1 | 10.19.0~dfsg-3ubuntu1.1 |
| nodejs | nodejs | >= 0 < 4.2.6~dfsg-1ubuntu4.2+esm2 | 4.2.6~dfsg-1ubuntu4.2+esm2 |
| nodejs | nodejs | >= 0 < 8.10.0~dfsg-2ubuntu0.4+esm2 | 8.10.0~dfsg-2ubuntu0.4+esm2 |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | mysql_cluster | <= 7.3.30 | — |
| oracle | mysql_cluster | 7.4.0 – 7.4.29 | — |
| oracle | mysql_cluster | 7.5.0 – 7.5.19 | — |
| oracle | mysql_cluster | 7.6.0 – 7.6.15 | — |
| oracle | mysql_cluster | 8.0.0 – 8.0.21 | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.1HIGH
vendor_oracle9.8HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-09-19·CVSS 7.5
CVE-2019-15604 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
Rogier Schouten discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-15604)
Ethan Rubinson discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15605)
Alyssa Wilk discovered that Node.js incorrectly handled
CISA ICS
Hitachi Energy FACTS Control Platform (FCP) Product
cisa_ics·2022-08-30·CVSS 3.7
[LOW] Hitachi Energy FACTS Control Platform (FCP) Product
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy FACTS Control Platform (FCP) Product
Last RevisedAugust 30, 2022
Alert CodeICSA-22-242-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: FACTS Control Platform (FCP) Product
- Vulnerability: Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to eavesdrop on the traffic betw
CISA ICS
Hitachi Energy Gateway Station (GWS) Product
cisa_ics·2022-08-30·CVSS 3.7
[LOW] Hitachi Energy Gateway Station (GWS) Product
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy Gateway Station (GWS) Product
Last RevisedAugust 30, 2022
Alert CodeICSA-22-242-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Gateway Station (GWS) Product
- Vulnerability: Inconsistent Interpretation of HTTP Requests, Use After Free, Classic Buffer Overflow, Integer Underflow, Improper Certificate Validation, Observable Discrepancy
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow unauthorized users to eavesdrop on the traffic between netwo
CISA ICS
Hitachi Energy MicroSCADA Pro/X SYS600
cisa_ics·2022-04-21
Hitachi Energy MicroSCADA Pro/X SYS600
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy MicroSCADA Pro/X SYS600
Last RevisedApril 21, 2022
Alert CodeICSA-22-111-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: MicroSCADA Pro/X SYS600
- Vulnerabilities: Observable Discrepancy, HTTP Request Smuggling, Classic Buffer Overflow, Improper Certificate Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Exposure of Sensitive Information to an Unauthorized Actor
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities coul
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) — CVE-2020-8174
vendor_oracle·2022-04-15·CVSS 8.1
CVE-2020-8174 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) — CVE-2020-8174
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (Node.js) vulnerability
CVE: CVE-2020-8174
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA ICS
Hitachi Energy e-mesh EMS
cisa_ics·2022-03-31·CVSS 8.1
[HIGH] Hitachi Energy e-mesh EMS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy e-mesh EMS
Last RevisedMarch 31, 2022
Alert CodeICSA-22-090-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: e-mesh EMS
- Vulnerabilities: Improper Restriction of Operations Within the Bounds of a Memory Buffer, Use After Free, Uncontrolled Resource Consumption
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following version of e-mesh EMS, an optimizer
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Core (Node.js) — CVE-2020-8174
vendor_oracle·2021-01-15·CVSS 9.8
CVE-2020-8174 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Core (Node.js) — CVE-2020-8174
Oracle Oracle Financial Services Applications Risk Matrix: Core (Node.js) vulnerability
CVE: CVE-2020-8174
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2020-8174
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-8174 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2020-8174
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) vulnerability
CVE: CVE-2020-8174
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Microsoft
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0.
vendor_msrc·2020-07-14·CVSS 8.1
CVE-2020-8174 [HIGH] CWE-191 napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0 12.18.0 and < 14.4.0.
napi_get_value_string_*() allows various kinds of memory corruption in node Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Re
Red Hat
nodejs: memory corruption in napi_get_value_string_* functions
vendor_redhat·2020-06-02·CVSS 8.1
CVE-2020-8174 [HIGH] CWE-119 nodejs: memory corruption in napi_get_value_string_* functions
nodejs: memory corruption in napi_get_value_string_* functions
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
A flaw was found in nodejs. Calling napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() with a non-NULL buf, and a bufsize of 0 will cause the entire string value to be written to buf, probably overrunning the length of the buffer.
Statement: NodeJS is a build time dependency of Red Hat Quay and is not used at runtime. Therefore this issue will not fixed in Quay 3.3.
Package: nodejs:14/nodejs (Red Hat Enterprise Linux 8) - Not affected
Package: nodejs (Red Hat Quay 3) - Will not fix
Debian
CVE-2020-8174: nodejs - napi_get_value_string_*() allows various kinds of memory corruption in node < 10...
vendor_debian·2020·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174: nodejs - napi_get_value_string_*() allows various kinds of memory corruption in node < 10...
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Scope: local
bookworm: resolved (fixed in 10.21.0~dfsg-1)
bullseye: resolved (fixed in 10.21.0~dfsg-1)
forky: resolved (fixed in 10.21.0~dfsg-1)
sid: resolved (fixed in 10.21.0~dfsg-1)
trixie: resolved (fixed in 10.21.0~dfsg-1)
OSV
nodejs vulnerabilities
osv·2023-09-19·CVSS 7.5
CVE-2019-15604 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
Rogier Schouten discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2019-15604)
Ethan Rubinson discovered that Node.js incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-15605)
Alyssa Wilk discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked in
GHSA
GHSA-gcvv-7whm-pv7c: napi_get_value_string_*() allows various kinds of memory corruption in node < 10
ghsa_unreviewed·2022-05-24
CVE-2020-8174 [HIGH] CWE-119 GHSA-gcvv-7whm-pv7c: napi_get_value_string_*() allows various kinds of memory corruption in node < 10
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
OSV
CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10
osv·2020-07-24·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppor
Bugzilla
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions
Calling napi_get_value_string_latin1(), napi_get_value_string_utf8(), or napi_get_value_string_utf16() with a non-NULL buf, and a bufsize of 0 will cause the entire string value to be written to buf, probably overrunning the length of the buffer.
Reference:
https://nodejs.org/en/blog/vulnerability/june-2020-security-releases/
Discussion:
Created nodejs tracking bugs for this issue:
Affects: epel-all [bug 1845263]
Affects: fedora-all [bug 1845257]
Created nodejs:10/nodejs tracking bugs for this issue:
Affects: fedora-all [bug 1845260]
Created nodejs:11/nodejs tracking bugs for this issue:
Affects: fedora-all [bug 1845258]
Created nodejs:12/nodejs tracking bugs for this issue:
Affects: fedora-all [bug
Bugzilla
CVE-2020-8174 nodejs:12/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs:12/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs:12/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2020-8174 nodejs:14/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs:14/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs:14/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2020-8174 nodejs:10/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs:10/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs:10/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [epel-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [epel-all]
CVE-2020-8174 nodejs: memory corruption in napi_get_value_string_* functions [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2020-8174 nodejs:11/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs:11/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs:11/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2020-8174 nodejs:13/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
bugzilla·2020-06-08·CVSS 8.1
CVE-2020-8174 [HIGH] CVE-2020-8174 nodejs:13/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
CVE-2020-8174 nodejs:13/nodejs: memory corruption in napi_get_value_string_* functions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
https://hackerone.com/reports/784186https://security.gentoo.org/glsa/202101-07https://security.netapp.com/advisory/ntap-20201023-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://hackerone.com/reports/784186https://security.gentoo.org/glsa/202101-07https://security.netapp.com/advisory/ntap-20201023-0003/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-07-24
Published