CVE-2020-8174
published 2020-07-24CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 10.21.0~dfsg-1 (bookworm) | nodejs 10.21.0~dfsg-1 (bookworm) |
| https | github.com_nodejs_node | — | — |
| msrc | cm1_nodejs_14.17.2-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node.js | < 10.21.0 | 10.21.0 |
| nodejs | node.js | >= 12.0.0 < 12.18.0 | 12.18.0 |
| nodejs | node.js | >= 14.0.0 < 14.4.0 | 14.4.0 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.21.0~dfsg-1 | 10.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.1 | 10.19.0~dfsg-3ubuntu1.1 |
| nodejs | nodejs | >= 0 < 4.2.6~dfsg-1ubuntu4.2+esm2 | 4.2.6~dfsg-1ubuntu4.2+esm2 |
| nodejs | nodejs | >= 0 < 8.10.0~dfsg-2ubuntu0.4+esm2 | 8.10.0~dfsg-2ubuntu0.4+esm2 |
| oracle | banking_extensibility_workbench | — | — |
| oracle | banking_extensibility_workbench | — | — |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | mysql_cluster | <= 7.3.30 | — |
| oracle | mysql_cluster | 7.4.0 – 7.4.29 | — |
| oracle | mysql_cluster | 7.5.0 – 7.5.19 | — |
| oracle | mysql_cluster | 7.6.0 – 7.6.15 | — |
| oracle | mysql_cluster | 8.0.0 – 8.0.21 | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| oracle | retail_xstore_point_of_service | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH