CVE-2021-44532
Summary
| CVE | CVE-2021-44532 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-24 19:15:00 UTC |
| Updated | 2022-10-05 14:00:00 UTC |
| Description | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| January 10th 2022 Security Releases | Node.js |
MISC |
nodejs.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| March 2022 Node.js Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Debian -- Security Information -- DSA-5170-1 nodejs |
DEBIAN |
www.debian.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160231 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2022-7830)
- 160361 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2022-9073-1)
- 179565 Debian Security Update for nodejs (DSA 5170-1)
- 183685 Debian Security Update for nodejs (CVE-2021-44532)
- 240414 Red Hat Update for rh-nodejs12-nodejs security (RHSA-2022:4914)
- 240747 Red Hat Update for rh-nodejs14-nodejs (RHSA-2022:7044)
- 240851 Red Hat Update for nodejs:14 (RHSA-2022:7830)
- 241026 Red Hat Update for nodejs:16 security (RHSA-2022:9073)
- 241341 Red Hat Update for nodejs:14 security (RHSA-2023:1742)
- 282257 Fedora Security Update for nodejs (FEDORA-2022-78090d2099)
- 282263 Fedora Security Update for nodejs (FEDORA-2022-0eda327cb4)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 354342 Amazon Linux Security Advisory for nodejs : ALAS2022-2022-214
- 354509 Amazon Linux Security Advisory for nodejs : ALAS2022-2022-019
- 354537 Amazon Linux Security Advisory for nodejs : ALAS-2022-214
- 355273 Amazon Linux Security Advisory for nodejs : ALAS2023-2023-084
- 376254 Node.js Improper Handling of URI Subject Alternative Names Vulnerability (JAN 2022)
- 500441 Alpine Linux Security Update for nodejs
- 501456 Alpine Linux Security Update for nodejs
- 501973 Alpine Linux Security Update for nodejs
- 502124 Alpine Linux Security Update for nodejs-current
- 502138 Alpine Linux Security Update for openjdk11
- 504210 Alpine Linux Security Update for nodejs
- 690825 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (972ba0e8-8b8a-11ec-b369-6c3be5272acd)
- 751613 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2022:0113-1)
- 751614 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2022:0112-1)
- 753115 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2022:0113-1)
- 753438 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2022:0112-1)
- 900719 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (8812)
- 901703 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (8818-1)
- 940775 AlmaLinux Security Update for nodejs:14 (ALSA-2022:7830)
- 940859 AlmaLinux Security Update for nodejs:16 (ALSA-2022:9073)
- 960636 Rocky Linux Security Update for nodejs:14 (RLSA-2022:7830)