CVE-2023-30588
published 2023-11-28CVE-2023-30588: When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.16%
63.8th percentile
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 18.19.0+dfsg-6~deb12u1 (bookworm) | nodejs 18.19.0+dfsg-6~deb12u1 (bookworm) |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.* | 12.* |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.* | 14.* |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.20.1 | 16.20.1 |
| nodejs | node | >= 17.0 < 17.* | 17.* |
| nodejs | node | >= 18.0 < 18.16.1 | 18.16.1 |
| nodejs | node | >= 19.0 < 19.* | 19.* |
| nodejs | node | >= 20.0 < 20.3.1 | 20.3.1 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | >= 16.0.0 < 16.20.1 | 16.20.1 |
| nodejs | node.js | >= 18.0.0 < 18.16.1 | 18.16.1 |
| nodejs | node.js | >= 20.0.0 < 20.3.1 | 20.3.1 |
| nodejs | nodejs | >= 0 < 18.19.0+dfsg-6~deb12u1 | 18.19.0+dfsg-6~deb12u1 |
| nodejs | nodejs | >= 0 < 18.13.0+dfsg1-1.1 | 18.13.0+dfsg1-1.1 |
| nodejs | nodejs | >= 0 < 18.13.0+dfsg1-1.1 | 18.13.0+dfsg1-1.1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.6 | 10.19.0~dfsg-3ubuntu1.6 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2024-04-16·CVSS 5.3
CVE-2023-30588 [MEDIUM] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
It was discovered that Node.js incorrectly handled the use of invalid public
keys while creating an x509 certificate. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker could
possibly use this issue to cause a denial of service. This issue only affected
Ubuntu 23.10. (CVE-2023-30588)
It was discovered that Node.js incorrectly handled the use of CRLF sequences to
delimit HTTP requests. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain unauthorised access. This issue only affected
Ubuntu 23.10. (CVE-2023-30589)
It was discovered that Node.js incorr
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
Red Hat
nodejs: process interuption due to invalid Public Key information in x509 certificates
vendor_redhat·2023-06-20·CVSS 5.3
CVE-2023-30588 [MEDIUM] nodejs: process interuption due to invalid Public Key information in x509 certificates
nodejs: process interuption due to invalid Public Key information in x509 certificates
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.
A vulnerability has been identified in the Node.js, where an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible
Debian
CVE-2023-30588: nodejs - When an invalid public key is used to create an x509 certificate using the crypt...
vendor_debian·2023·CVSS 5.3
CVE-2023-30588 [MEDIUM] CVE-2023-30588: nodejs - When an invalid public key is used to create an x509 certificate using the crypt...
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.
Scope: local
bookworm: resolved (fixed in 18.19.0+dfsg-6~deb12u1)
bullseye: resolved
forky: resolved (fixed in 18.13.0+dfsg1-1.1)
sid: resolved (fixed in 18.13.0+dfsg1-1.1)
trixie: resolved (fixed in 18.13.0+dfsg1-1.1)
OSV
nodejs vulnerabilities
osv·2024-04-16·CVSS 5.3
CVE-2023-30588 [MEDIUM] nodejs vulnerabilities
nodejs vulnerabilities
It was discovered that Node.js incorrectly handled the use of invalid public
keys while creating an x509 certificate. If a user or an automated system were
tricked into opening a specially crafted input file, a remote attacker could
possibly use this issue to cause a denial of service. This issue only affected
Ubuntu 23.10. (CVE-2023-30588)
It was discovered that Node.js incorrectly handled the use of CRLF sequences to
delimit HTTP requests. If a user or an automated system were tricked into
opening a specially crafted input file, a remote attacker could possibly use
this issue to obtain unauthorised access. This issue only affected
Ubuntu 23.10. (CVE-2023-30589)
It was discovered that Node.js incorrectly described the generateKeys()
function in the documentation.
OSV
CVE-2023-30588: When an invalid public key is used to create an x509 certificate using the crypto
osv·2023-11-28·CVSS 5.3
CVE-2023-30588 [MEDIUM] CVE-2023-30588: When an invalid public key is used to create an x509 certificate using the crypto
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.
GHSA
GHSA-g526-x7vj-cfv6: When an invalid public key is used to create an x509 certificate using the crypto
ghsa_unreviewed·2023-11-28
CVE-2023-30588 [MEDIUM] GHSA-g526-x7vj-cfv6: When an invalid public key is used to create an x509 certificate using the crypto
When an invalid public key is used to create an x509 certificate using the crypto.X509Certificate() API a non-expect termination occurs making it susceptible to DoS attacks when the attacker could force interruptions of application processing, as the process terminates when accessing public key info of provided certificates from user code. The current context of the users will be gone, and that will cause a DoS scenario. This vulnerability affects all active Node.js versions v16, v18, and, v20.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://nodejs.org/en/blog/vulnerability/june-2023-security-releaseshttps://security.netapp.com/advisory/ntap-20240621-0006/https://nodejs.org/en/blog/vulnerability/june-2023-security-releaseshttps://security.netapp.com/advisory/ntap-20240621-0006/https://security.netapp.com/advisory/ntap-20241101-0011/
2023-11-28
Published