nodejs-bl: buffer over-read vulnerability leads to corrupted BufferList which can result in uninitialized memory being leaked
Published Aug 30, 2020
6.5
MEDIUMCVSS 3.1
EPSS 2.18%
Description
A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.
Affected products
- Vendor n/a Product BL Defaultn/a
- Version Fixed in 4.0.3, 3.0.1, 2.2.1, and 1.2.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | BL | n/a |
|
Configuration 1
- < 1.2.3
- ≥ 2.0.0 · < 2.2.1
- ≥ 3.0.0 · < 3.0.1
- ≥ 4.0.0 · < 4.0.3
Configuration 2
- 9.0
No data.
Red Hat OpenShift Container Platform 3.11
kibana
Will not fix
Red Hat OpenShift Container Platform 4
kibana
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-logging-kibana6
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | kibana | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-logging-kibana6 | Not affected | n/a |
bl
npm
Introduced 0 Fixed 1.2.3bl
npm
Introduced 2.0.0 Fixed 2.2.1bl
npm
Introduced 3.0.0 Fixed 3.0.1bl
npm
Introduced 4.0.0 Fixed 4.0.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | bl | 0 | 1.2.3 |
| npm | bl | 2.0.0 | 2.2.1 |
| npm | bl | 3.0.0 | 3.0.1 |
| npm | bl | 4.0.0 | 4.0.3 |
Remediation
Red Hat statement
Red Hat OpenShift Container Platform 4 delivers the kibana package where the nodejs-bl module is used, but during the update to container first (to openshift4/ose-logging-kibana6) the dependency was removed and hence kibana package is marked as wontfix. This may be fixed in the future.
References (11)
- https://access.redhat.com/security/cve/CVE-2020-8244 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1874775 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1218 Advisory
- https://github.com/advisories/GHSA-pp7h-53gx-mx7r Advisory
- https://github.com/rvagg/bl/commit/8a8c13c880e2bef519133ea43e0e9b78b5d0c91e
- https://github.com/rvagg/bl/commit/d3e240e3b8ba4048d3c76ef5fb9dd1f8872d3190
- https://github.com/rvagg/bl/commit/dacc4ac7d5fcd6201bcf26fbd886951be9537466
- https://hackerone.com/reports/966347 x_refsource_MISCExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00028.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8244
- https://www.cve.org/CVERecord?id=CVE-2020-8244
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8244 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1874775 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-1218 | Advisory | |
| https://github.com/advisories/GHSA-pp7h-53gx-mx7r | Advisory | |
| https://github.com/rvagg/bl/commit/8a8c13c880e2bef519133ea43e0e9b78b5d0c91e | ||
| https://github.com/rvagg/bl/commit/d3e240e3b8ba4048d3c76ef5fb9dd1f8872d3190 | ||
| https://github.com/rvagg/bl/commit/dacc4ac7d5fcd6201bcf26fbd886951be9537466 | ||
| https://hackerone.com/reports/966347 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/06/msg00028.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8244 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8244 |
Change history (0)
No recorded changes yet.