Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-22940

Опубликовано: 11 авг. 2021
Источник: redhat
CVSS3: 7.5

Описание

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

A flaw was found in Node.js, where it is vulnerable to a use-after-free attack. This flaw allows an attacker to exploit memory corruption to change process behavior. The highest threat from this vulnerability is to confidentiality and integrity.

Отчет

This issue is a follow-up to CVE-2021-22930, as the issue was not completely resolved in the fix for CVE-2021-22930. Node.js as shipped in Red Hat Enterprise Linux 8 streams and Red Hat Software Collections is not explicitly affected by the incomplete fix because the incomplete fix was not released, but the original issue does affect these components. Red Hat Quay from version 3.4 consumes nodejs from RHEL, so security tracking is provided by the container health index on the customer portal [1]. Additionally there is no impact from this issue on Quay 3.3 and 3.2 because nodejs is only used at build time and is no longer shipped, starting with Quay 3.5 [2]. [1] https://catalog.redhat.com/software/containers/quay/quay-rhel8/600e03aadd19c7786c43ae49?container-tabs=security [2] https://issues.redhat.com/browse/PROJQUAY-1409 Therefore Quay component is marked as "Will not fix" with impact LOW.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8nodejs:16/nodejsNot affected
Red Hat Enterprise Linux 9nodejsNot affected
Red Hat Quay 3quay/quay-rhel8Will not fix
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:362321.09.2021
Red Hat Enterprise Linux 8nodejsFixedRHSA-2021:366627.09.2021
Red Hat Enterprise Linux 8.1 Extended Update SupportnodejsFixedRHSA-2021:363922.09.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportnodejsFixedRHSA-2021:363822.09.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs14-nodejsFixedRHSA-2021:328026.08.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejsFixedRHSA-2021:328126.08.2021
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nodejs12-nodejs-nodemonFixedRHSA-2021:328126.08.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1993029nodejs: Use-after-free on close http2 on stream canceling

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
nvd
почти 4 года назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
debian
почти 4 года назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use aft ...

CVSS3: 7.5
github
около 3 лет назад

Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

CVSS3: 7.5
fstec
почти 4 года назад

Уязвимость программной платформы Node.js, связанная с использованием памяти после её освобождения, позволяющая нарушителю оказать воздействие на целостность данных

7.5 High

CVSS3