CVE-2023-23919
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- nodejs/node.js
- Source
- support@hackerone.com
References
- https://hackerone.com/reports/1808596Exploit, Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230316-0008/
- https://hackerone.com/reports/1808596Exploit, Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/Patch, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230316-0008/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.