SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-44533

Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the…

MEDIUM 5.3EPSS 9.36%

Does this matter?

Lower severity and a low EPSS score (9.36%). Track it; it rarely justifies an emergency change on its own.

Description

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
9.36% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
nodejs/node.js · oracle/graalvm · oracle/mysql cluster · oracle/mysql connectors · oracle/mysql enterprise monitor · oracle/mysql server · oracle/mysql workbench · oracle/peoplesoft enterprise peopletools · debian/debian linux
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.