Back

MEDIUM

nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked

Published Aug 30, 2020

Description

A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.

Affected products

Remediation

Red Hat statement

Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-bl module is used, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Aug 30, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 30, 2020
ENISA EUVD
Assigner hackerone
Published Aug 30, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-1218 GHSA-PP7H-53GX-MX7R