nodejs: Incorrect handling of certificate subject and issuer fields
Published Feb 24, 2022
7.4
HIGHCVSS 3.1
EPSS 9.36%
Description
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.22.9
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.18.3
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.13.2
- Version 17.0StatusaffectedConstraints<17.3.1
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
Configuration 1
Configuration 2
- 20.3.5
- 21.3.1
- 22.0.0.2
- < 8.0.29
- 8.0.29
- ≤ 8.0.28
- ≤ 8.0.29
- ≤ 5.7.37
- ≥ 8.0.0 · ≤ 8.0.28
- ≤ 8.0.28
- 8.58
- 8.59
Configuration 3
- 11.0
No data.
RHODF-4.13-RHEL-9
odf4/mcg-core-rhel9:v4.13.0-41
Fixed · RHSA-2023:3742
Red Hat Enterprise Linux 8
nodejs:12-8060020220523160029.ad008a3a
Fixed · RHEA-2022:5139
Red Hat Enterprise Linux 8
nodejs:14-8070020221020110846.bd1311ed
Fixed · RHSA-2022:7830
Red Hat Enterprise Linux 8
nodejs:16-8070020221207164159.bd1311ed
Fixed · RHSA-2022:9073
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
nodejs:12-8010020220518102644.c27ad7f8
Fixed · RHEA-2022:4925
Red Hat Enterprise Linux 8.2 Extended Update Support
nodejs:12-8020020220523154454.4cda2c84
Fixed · RHEA-2022:5221
Red Hat Enterprise Linux 8.4 Extended Update Support
nodejs:12-8040020220523155137.522a0ee4
Fixed · RHEA-2022:5615
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:14-8060020230306170237.ad008a3a
Fixed · RHSA-2023:1742
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.22.12-2.el7
Fixed · RHSA-2022:4914
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.20.1-2.el7
Fixed · RHSA-2022:7044
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Quay 3
nodejs
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHODF-4.13-RHEL-9 | odf4/mcg-core-rhel9:v4.13.0-41 | Fixed | RHSA-2023:3742 |
| Red Hat Enterprise Linux 8 | nodejs:12-8060020220523160029.ad008a3a | Fixed | RHEA-2022:5139 |
| Red Hat Enterprise Linux 8 | nodejs:14-8070020221020110846.bd1311ed | Fixed | RHSA-2022:7830 |
| Red Hat Enterprise Linux 8 | nodejs:16-8070020221207164159.bd1311ed | Fixed | RHSA-2022:9073 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | nodejs:12-8010020220518102644.c27ad7f8 | Fixed | RHEA-2022:4925 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | nodejs:12-8020020220523154454.4cda2c84 | Fixed | RHEA-2022:5221 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs:12-8040020220523155137.522a0ee4 | Fixed | RHEA-2022:5615 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:14-8060020230306170237.ad008a3a | Fixed | RHSA-2023:1742 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.22.12-2.el7 | Fixed | RHSA-2022:4914 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.20.1-2.el7 | Fixed | RHSA-2022:7044 |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Quay 3 | nodejs | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Quay from version 3.4 consumes nodejs from RHEL, so security tracking is provided by the container health index on the customer portal [1]. Additionally, there is no impact from this issue on Quay 3.3 and 3.2 because nodejs is only used at build time and is no longer shipped, starting with Quay 3.5 [2]. [1] https://catalog.redhat.com/software/containers/quay/quay-rhel8/600e03aadd19c7786c43ae49?container-tabs=security [2] https://issues.redhat.com/browse/PROJQUAY-1409 Therefore, the Quay component is marked as "Will not fix" with impact LOW.
References (11)
- https://access.redhat.com/security/cve/CVE-2021-44533 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2040856 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31364 Advisory
- https://hackerone.com/reports/1429694 x_refsource_MISCExploitMitigationThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ x_refsource_MISCRelease NotesVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-44533
- https://security.netapp.com/advisory/ntap-20220325-0007/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-44533
- https://www.debian.org/security/2022/dsa-5170 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-44533 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2040856 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-31364 | Advisory | |
| https://hackerone.com/reports/1429694 | x_refsource_MISCExploitMitigationThird Party Advisory | |
| https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/ | x_refsource_MISCRelease NotesVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-44533 | ||
| https://security.netapp.com/advisory/ntap-20220325-0007/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-44533 | ||
| https://www.debian.org/security/2022/dsa-5170 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory | |
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.