CVE-2021-44533

MEDIUMCVSS 5.3/10EPSS 9.36%

Last modified

CVE-2021-44533 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. EPSS estimates a 9.36% chance of exploitation in the next 30 days.

Description

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS Probability
9.36%

94.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NodejsNode.Js< 12.22.9
NodejsNode.Js>= 14.0.0, < 14.18.3
NodejsNode.Js>= 16.0.0, < 16.13.2
NodejsNode.Js>= 17.0.0, < 17.3.1
OracleGraalvm20.3.5
OracleGraalvm21.3.1
OracleGraalvm22.0.0.2
OracleMysql Cluster< 8.0.29
OracleMysql Cluster8.0.29
OracleMysql Connectors<= 8.0.28
OracleMysql Enterprise Monitor<= 8.0.29
OracleMysql Server<= 5.7.37
OracleMysql Server>= 8.0.0, <= 8.0.28
OracleMysql Workbench<= 8.0.28
OraclePeoplesoft Enterprise Peopletools8.58
OraclePeoplesoft Enterprise Peopletools8.59
DebianDebian Linux11.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-44533?
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
How severe is CVE-2021-44533?
CVE-2021-44533 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 9.36% probability of exploitation in the next 30 days.
How do I fix CVE-2021-44533?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-44533?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST