nodejs: Certificate Verification Bypass via String Injection
Published Feb 24, 2022
7.4
HIGHCVSS 3.1
EPSS 10.36%
Description
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.
Affected products
-
Affected
- ≥ 10.0, < 10.*
- ≥ 11.0, < 11.*
- ≥ 12.0, < 12.22.9
- ≥ 13.0, < 13.*
- ≥ 14.0, < 14.18.3
- ≥ 15.0, < 15.*
- ≥ 16.0, < 16.13.2
- ≥ 17.0, < 17.3.1
- ≥ 4.0, < 4.*
- ≥ 5.0, < 5.*
- ≥ 6.0, < 6.*
- ≥ 7.0, < 7.*
- ≥ 8.0, < 8.*
- ≥ 9.0, < 9.*
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
Configuration 1
Configuration 2
- 20.3.5
- 21.3.1
- 22.0.0.2
- ≤ 8.0.29
- ≤ 8.0.28
- ≤ 8.0.29
- ≤ 5.7.37
- ≥ 8.0.0 · ≤ 8.0.28
- ≥ 8.0.0 · ≤ 8.0.28
- 8.58
- 8.59
Configuration 3
- 11.0
No data.
RHODF-4.13-RHEL-9
odf4/mcg-core-rhel9:v4.13.0-41
Fixed · RHSA-2023:3742
Red Hat Enterprise Linux 8
nodejs:12-8060020220523160029.ad008a3a
Fixed · RHEA-2022:5139
Red Hat Enterprise Linux 8
nodejs:14-8070020221020110846.bd1311ed
Fixed · RHSA-2022:7830
Red Hat Enterprise Linux 8
nodejs:16-8070020221207164159.bd1311ed
Fixed · RHSA-2022:9073
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
nodejs:12-8010020220518102644.c27ad7f8
Fixed · RHEA-2022:4925
Red Hat Enterprise Linux 8.2 Extended Update Support
nodejs:12-8020020220523154454.4cda2c84
Fixed · RHEA-2022:5221
Red Hat Enterprise Linux 8.4 Extended Update Support
nodejs:12-8040020220523155137.522a0ee4
Fixed · RHEA-2022:5615
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:14-8060020230306170237.ad008a3a
Fixed · RHSA-2023:1742
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.22.12-2.el7
Fixed · RHSA-2022:4914
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.20.1-2.el7
Fixed · RHSA-2022:7044
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Quay 3
nodejs
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHODF-4.13-RHEL-9 | odf4/mcg-core-rhel9:v4.13.0-41 | Fixed | RHSA-2023:3742 |
| Red Hat Enterprise Linux 8 | nodejs:12-8060020220523160029.ad008a3a | Fixed | RHEA-2022:5139 |
| Red Hat Enterprise Linux 8 | nodejs:14-8070020221020110846.bd1311ed | Fixed | RHSA-2022:7830 |
| Red Hat Enterprise Linux 8 | nodejs:16-8070020221207164159.bd1311ed | Fixed | RHSA-2022:9073 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | nodejs:12-8010020220518102644.c27ad7f8 | Fixed | RHEA-2022:4925 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | nodejs:12-8020020220523154454.4cda2c84 | Fixed | RHEA-2022:5221 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs:12-8040020220523155137.522a0ee4 | Fixed | RHEA-2022:5615 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:14-8060020230306170237.ad008a3a | Fixed | RHSA-2023:1742 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.22.12-2.el7 | Fixed | RHSA-2022:4914 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.20.1-2.el7 | Fixed | RHSA-2022:7044 |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Quay from version 3.4 consumes nodejs from RHEL, so security tracking is provided by the container health index on the customer portal [1]. Additionally there is no impact from this issue on Quay 3.3 and 3.2 because nodejs is only used at build time and is no longer shipped, starting with Quay 3.5 [2]. [1] https://catalog.redhat.com/software/containers/quay/quay-rhel8/600e03aadd19c7786c43ae49?container-tabs=security [2] https://issues.redhat.com/browse/PROJQUAY-1409 Therefore Quay component is marked as "Will not fix" with impact LOW.
References (11)
- https://access.redhat.com/security/cve/CVE-2021-44532 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2040846 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31363 Advisory
- https://hackerone.com/reports/1429694 x_refsource_MISCMitigationThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ x_refsource_MISCExploitRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44532
- https://security.netapp.com/advisory/ntap-20220325-0007/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-44532
- https://www.debian.org/security/2022/dsa-5170 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-44532 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2040846 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31363 | Advisory | |
| https://hackerone.com/reports/1429694 | x_refsource_MISCMitigationThird Party Advisory | |
| https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ | x_refsource_MISCExploitRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-44532 | ||
| https://security.netapp.com/advisory/ntap-20220325-0007/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-44532 | ||
| https://www.debian.org/security/2022/dsa-5170 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data