napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
La función napi_get_value_string_*(), permite varios tipos de corrupción de memoria en node versiones anteriores a 10.21.0, 12.18.0 y versiones anteriores a 14.4.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AV:N/AC:M/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | MEDIUM |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-119
|
| [email protected] | Primary |
en
CWE-191
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9ccd2a540> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9ccd29840> | Application |
| nodejs | node.js | * | <built-in method update of dict object at 0x72a9cd08e980> | Application |
| oracle | banking_extensibility_workbench | 14.3.0 | <built-in method update of dict object at 0x72a9ccd29f80> | Application |
| oracle | banking_extensibility_workbench | 14.4.0 | <built-in method update of dict object at 0x72a9ccd2ba00> | Application |
| oracle | blockchain_platform | * | <built-in method update of dict object at 0x72a9ccd2bac0> | Application |
| oracle | mysql_cluster | * | <built-in method update of dict object at 0x72a9cc81a780> | Application |
| oracle | mysql_cluster | * | <built-in method update of dict object at 0x72a9ccd28d00> | Application |
| oracle | mysql_cluster | * | <built-in method update of dict object at 0x72a9cd0d9b40> | Application |
| oracle | mysql_cluster | * | <built-in method update of dict object at 0x72a9ccd2b100> | Application |
| oracle | mysql_cluster | * | <built-in method update of dict object at 0x72a9cc6793c0> | Application |
| oracle | retail_xstore_point_of_service | 16.0.6 | <built-in method update of dict object at 0x72a9ccd29c00> | Application |
| oracle | retail_xstore_point_of_service | 17.0.4 | <built-in method update of dict object at 0x72a9cd0d9cc0> | Application |
| oracle | retail_xstore_point_of_service | 18.0.3 | <built-in method update of dict object at 0x72a9b0b38f80> | Application |
| oracle | retail_xstore_point_of_service | 19.0.2 | <built-in method update of dict object at 0x72a9cc6db640> | Application |
| oracle | retail_xstore_point_of_service | 20.0.1 | <built-in method update of dict object at 0x72a9cc6780c0> | Application |
| netapp | active_iq_unified_manager | - | <built-in method update of dict object at 0x72a9cc81b280> | Application |
| netapp | active_iq_unified_manager | - | <built-in method update of dict object at 0x72a9ccf9f0c0> | Application |
| netapp | oncommand_insight | - | <built-in method update of dict object at 0x72a9cc6791c0> | Application |
| netapp | oncommand_workflow_automation | - | <built-in method update of dict object at 0x72a9ccd2b080> | Application |
| netapp | snapcenter | - | <built-in method update of dict object at 0x72a9cc81a240> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Yes | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:banking_extensibility_workbench:14.4.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| Yes | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| Yes | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |