HIGH · 8.1

CVE-2020-8174

napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.

Vulnerability Description

napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NodejsNode.Js< 10.21.0
OracleBanking Extensibility Workbench14.3.0
OracleBlockchain Platform< 21.1.2
OracleMysql Cluster<= 7.3.30
OracleRetail Xstore Point Of Service16.0.6
NetappActive Iq Unified Manager-
NetappOncommand Insight-
NetappOncommand Workflow Automation-
NetappSnapcenter-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8174?

CVE-2020-8174 is a vulnerability with a CVSS score of 8.1 (HIGH). napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.

How severe is CVE-2020-8174?

CVE-2020-8174 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8174?

Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js, Oracle Banking Extensibility Workbench, Oracle Blockchain Platform, Oracle Mysql Cluster, Oracle Retail Xstore Point Of Service.