CVE-2021-44533
Summary
| CVE | CVE-2021-44533 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-24 19:15:00 UTC |
| Updated | 2022-10-06 02:28:00 UTC |
| Description | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| January 10th 2022 Security Releases | Node.js |
MISC |
nodejs.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| March 2022 Node.js Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| Debian -- Security Information -- DSA-5170-1 nodejs |
DEBIAN |
www.debian.org |
|
| Oracle Critical Patch Update Advisory - July 2022 |
N/A |
www.oracle.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160231 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2022-7830)
- 160361 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2022-9073-1)
- 179565 Debian Security Update for nodejs (DSA 5170-1)
- 182247 Debian Security Update for nodejs (CVE-2021-44533)
- 240414 Red Hat Update for rh-nodejs12-nodejs security (RHSA-2022:4914)
- 240747 Red Hat Update for rh-nodejs14-nodejs (RHSA-2022:7044)
- 240851 Red Hat Update for nodejs:14 (RHSA-2022:7830)
- 241026 Red Hat Update for nodejs:16 security (RHSA-2022:9073)
- 241341 Red Hat Update for nodejs:14 security (RHSA-2023:1742)
- 282257 Fedora Security Update for nodejs (FEDORA-2022-78090d2099)
- 282263 Fedora Security Update for nodejs (FEDORA-2022-0eda327cb4)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 354342 Amazon Linux Security Advisory for nodejs : ALAS2022-2022-214
- 354509 Amazon Linux Security Advisory for nodejs : ALAS2022-2022-019
- 354537 Amazon Linux Security Advisory for nodejs : ALAS-2022-214
- 355273 Amazon Linux Security Advisory for nodejs : ALAS2023-2023-084
- 376254 Node.js Improper Handling of URI Subject Alternative Names Vulnerability (JAN 2022)
- 376547 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUAPR2022)
- 500441 Alpine Linux Security Update for nodejs
- 501456 Alpine Linux Security Update for nodejs
- 501973 Alpine Linux Security Update for nodejs
- 502124 Alpine Linux Security Update for nodejs-current
- 502138 Alpine Linux Security Update for openjdk11
- 504210 Alpine Linux Security Update for nodejs
- 690825 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (972ba0e8-8b8a-11ec-b369-6c3be5272acd)
- 751613 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2022:0113-1)
- 751614 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2022:0112-1)
- 753115 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2022:0113-1)
- 753438 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2022:0112-1)
- 900720 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (8813)
- 901555 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (8819-1)
- 940775 AlmaLinux Security Update for nodejs:14 (ALSA-2022:7830)
- 940859 AlmaLinux Security Update for nodejs:16 (ALSA-2022:9073)
- 960636 Rocky Linux Security Update for nodejs:14 (RLSA-2022:7830)