nodejs: memory corruption in napi_get_value_string_* functions
Published Jul 24, 2020
8.1
HIGHCVSS 3.1
EPSS 7.65%
Description
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Affected products
No data.
Configuration 1
Configuration 2
- 14.3.0
- 14.4.0
- < 21.1.2
- ≤ 7.3.30
- ≥ 7.4.0 · ≤ 7.4.29
- ≥ 7.5.0 · ≤ 7.5.19
- ≥ 7.6.0 · ≤ 7.6.15
- ≥ 8.0.0 · ≤ 8.0.21
- 16.0.6
- 17.0.4
- 18.0.3
- 19.0.2
- 20.0.1
Configuration 3
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
nodejs:10-8020020200617141353.4cda2c84
Fixed · RHSA-2020:2848
Red Hat Enterprise Linux 8
nodejs:12-8020020200630155331.4cda2c84
Fixed · RHSA-2020:2852
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nodejs:10-8000020200617115915.f8e95b4e
Fixed · RHSA-2020:3042
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:10-8010020200617134056.c27ad7f8
Fixed · RHSA-2020:2849
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:12-8010020200630154708.c27ad7f8
Fixed · RHSA-2020:2847
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
Red Hat Quay 3
nodejs
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8020020200617141353.4cda2c84 | Fixed | RHSA-2020:2848 |
| Red Hat Enterprise Linux 8 | nodejs:12-8020020200630155331.4cda2c84 | Fixed | RHSA-2020:2852 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs:10-8000020200617115915.f8e95b4e | Fixed | RHSA-2020:3042 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:10-8010020200617134056.c27ad7f8 | Fixed | RHSA-2020:2849 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:12-8010020200630154708.c27ad7f8 | Fixed | RHSA-2020:2847 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
NodeJS is a build time dependency of Red Hat Quay and is not used at runtime. Therefore this issue will not fixed in Quay 3.3.
References (12)
- https://access.redhat.com/security/cve/CVE-2020-8174 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1845256 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29058 Advisory
- https://hackerone.com/reports/784186 x_refsource_MISCExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8174
- https://security.gentoo.org/glsa/202101-07 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20201023-0003/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8174
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8174 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1845256 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29058 | Advisory | |
| https://hackerone.com/reports/784186 | x_refsource_MISCExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8174 | ||
| https://security.gentoo.org/glsa/202101-07 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://security.netapp.com/advisory/ntap-20201023-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-8174 | ||
| https://www.oracle.com//security-alerts/cpujul2021.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpujan2021.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuoct2020.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data