CVE-2021-44533
published 2022-02-24CVE-2021-44533: Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate…
PriorityP434medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
9.36%
94.8th percentile
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nodejs | < nodejs 12.22.9~dfsg-1 (bookworm) | nodejs 12.22.9~dfsg-1 (bookworm) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.22.9 | 12.22.9 |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.18.3 | 14.18.3 |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.13.2 | 16.13.2 |
| nodejs | node | >= 17.0 < 17.3.1 | 17.3.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | < 12.22.9 | 12.22.9 |
| nodejs | node.js | >= 14.0.0 < 14.18.3 | 14.18.3 |
| nodejs | node.js | >= 16.0.0 < 16.13.2 | 16.13.2 |
| nodejs | node.js | >= 17.0.0 < 17.3.1 | 17.3.1 |
| nodejs | nodejs | >= 0 < 12.22.12~dfsg-1~deb11u1 | 12.22.12~dfsg-1~deb11u1 |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1 | 12.22.9~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1 | 12.22.9~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1 | 12.22.9~dfsg-1 |
| oracle | graalvm | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) — CVE-2021-44533
vendor_oracle·2022-04-15·CVSS 5.3
CVE-2021-44533 [MEDIUM] Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) — CVE-2021-44533
Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) vulnerability
CVE: CVE-2021-44533
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
nodejs: Incorrect handling of certificate subject and issuer fields
vendor_redhat·2022-01-10·CVSS 5.3
CVE-2021-44533 [MEDIUM] CWE-295 nodejs: Incorrect handling of certificate subject and issuer fields
nodejs: Incorrect handling of certificate subject and issuer fields
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
A flaw was found in node.js, where it did not properly handle multi-value Re
Debian
CVE-2021-44533: nodejs - Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value...
vendor_debian·2021·CVSS 5.3
CVE-2021-44533 [MEDIUM] CVE-2021-44533: nodejs - Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value...
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
Scope: local
bookworm: resolved (fixed in 12.22.9~dfsg-1)
bullseye: resolved (fixed in 12.22.12~dfsg-1~deb11u1)
forky: resolved (fixed in 12.22.9~
OSV
CVE-2021-44533: Node
osv·2022-02-24·CVSS 5.3
CVE-2021-44533 [MEDIUM] CVE-2021-44533: Node
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://hackerone.com/reports/1429694https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/https://security.netapp.com/advisory/ntap-20220325-0007/https://www.debian.org/security/2022/dsa-5170https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://hackerone.com/reports/1429694https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/https://security.netapp.com/advisory/ntap-20220325-0007/https://www.debian.org/security/2022/dsa-5170https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2022-02-24
Published