HIGH · 7.4

CVE-2021-44531

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, ...

Vulnerability Description

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NodejsNode.Js< 12.22.9
OracleGraalvm20.3.5
OracleMysql Connectors<= 8.0.28
OracleMysql Enterprise Monitor<= 8.0.29
OracleMysql Server<= 5.7.37
OracleMysql Workbench<= 8.0.28
OraclePeoplesoft Enterprise Peopletools8.58
OracleMysql Cluster<= 8.0.29

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-44531?

CVE-2021-44531 is a vulnerability with a CVSS score of 7.4 (HIGH). Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, ...

How severe is CVE-2021-44531?

CVE-2021-44531 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-44531?

Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js, Oracle Graalvm, Oracle Mysql Connectors, Oracle Mysql Enterprise Monitor, Oracle Mysql Server.