{"api_version":"1","generated_at":"2026-07-23T11:01:28+00:00","cve":"CVE-2020-8244","urls":{"html":"https://cve.report/CVE-2020-8244","api":"https://cve.report/api/cve/CVE-2020-8244.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-8244","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-8244"},"summary":{"title":"CVE-2020-8244","description":"A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.","state":"PUBLIC","assigner":"support@hackerone.com","published_at":"2020-08-30 15:15:00","updated_at":"2022-05-24 17:31:00"},"problem_types":["CWE-125"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00028.html","name":"[debian-lts-announce] 20210630 [SECURITY] [DLA 2698-1] node-bl security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2698-1] node-bl security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://hackerone.com/reports/966347","name":"https://hackerone.com/reports/966347","refsource":"MISC","tags":["Exploit","Patch","Third Party Advisory"],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-8244","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8244","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"8244","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bufferlist_project","cpe5":"bufferlist","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"8244","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bufferlist_project","cpe5":"bufferlist","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"8244","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-8244","qid":"178691","title":"Debian Security Update for node-bl (DLA 2698-1)"},{"cve":"CVE-2020-8244","qid":"198527","title":"Ubuntu Security Notification for bl Vulnerability (USN-5098-1)"},{"cve":"CVE-2020-8244","qid":"982627","title":"Nodejs (npm) Security Update for bl (GHSA-pp7h-53gx-mx7r)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-8244","ASSIGNER":"support@hackerone.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"bl","version":{"version_data":[{"version_value":"Fixed in 4.0.3, 3.0.1, 2.2.1, and 1.2.3"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Buffer Over-read (CWE-126)"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://hackerone.com/reports/966347","url":"https://hackerone.com/reports/966347"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210630 [SECURITY] [DLA 2698-1] node-bl security update","url":"https://lists.debian.org/debian-lts-announce/2021/06/msg00028.html"}]},"description":{"description_data":[{"lang":"eng","value":"A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls."}]}},"nvd":{"publishedDate":"2020-08-30 15:15:00","lastModifiedDate":"2022-05-24 17:31:00","problem_types":["CWE-125"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":2.5},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bufferlist_project:bufferlist:*:*:*:*:*:node.js:*:*","versionStartIncluding":"3.0.0","versionEndExcluding":"3.0.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bufferlist_project:bufferlist:*:*:*:*:*:node.js:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.0.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bufferlist_project:bufferlist:*:*:*:*:*:node.js:*:*","versionEndExcluding":"1.2.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:bufferlist_project:bufferlist:*:*:*:*:*:node.js:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.2.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"8244","Ordinal":"168581","Title":"CVE-2020-8244","CVE":"CVE-2020-8244","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"8244","Ordinal":"1","NoteData":"A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the BufferList state can be corrupted, tricking it into exposing uninitialized memory via regular .slice() calls.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"8244","Ordinal":"2","NoteData":"2020-08-30","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"8244","Ordinal":"3","NoteData":"2021-06-30","Type":"Other","Title":"Modified"}]}}}