Description
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5170-1 | nodejs security update |
EUVD |
EUVD-2021-31364 | Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable. |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Nodejs
Subscribe
Node.js
Subscribe
Oracle
Subscribe
Graalvm
Subscribe
Mysql Cluster
Subscribe
Mysql Connectors
Subscribe
Mysql Enterprise Monitor
Subscribe
Mysql Server
Subscribe
Mysql Workbench
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Openshift Data Foundation
Subscribe
Rhel E4s
Subscribe
Rhel Eus
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T22:24:40.708Z
Reserved: 2021-12-02T00:00:00.000Z
Link: CVE-2021-44533
No data.
Status : Modified
Published: 2022-02-24T19:15:09.407
Modified: 2024-11-21T06:31:10.940
Link: CVE-2021-44533
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD