CVE-2019-15604

I

mproper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/746733 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Patch Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/746733 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm:19.3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm:20.0.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 04:29

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html - Mailing List, Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0573 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0573 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0579 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0579 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0597 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0597 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0598 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0598 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0602 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0602 - Third Party Advisory
References () https://hackerone.com/reports/746733 - Exploit, Third Party Advisory () https://hackerone.com/reports/746733 - Exploit, Third Party Advisory
References () https://nodejs.org/en/blog/release/v10.19.0/ - Release Notes, Vendor Advisory () https://nodejs.org/en/blog/release/v10.19.0/ - Release Notes, Vendor Advisory
References () https://nodejs.org/en/blog/release/v12.15.0/ - Release Notes, Vendor Advisory () https://nodejs.org/en/blog/release/v12.15.0/ - Release Notes, Vendor Advisory
References () https://nodejs.org/en/blog/release/v13.8.0/ - Vendor Advisory () https://nodejs.org/en/blog/release/v13.8.0/ - Vendor Advisory
References () https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ - Vendor Advisory () https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ - Vendor Advisory
References () https://security.gentoo.org/glsa/202003-48 - Third Party Advisory () https://security.gentoo.org/glsa/202003-48 - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20200221-0004/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20200221-0004/ - Third Party Advisory
References () https://www.debian.org/security/2020/dsa-4669 - Third Party Advisory () https://www.debian.org/security/2020/dsa-4669 - Third Party Advisory
References () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory