Improper certificate validation vulnerability in Node.js - CVE-2021-44531ID: oval:org.secpod.oval:def:96767 | Date: (C)2024-01-12 (M)2024-06-24 |
Class: VULNERABILITY | Family: windows |
The host is installed with Node.js 12.x before 12.22.9, 14.x before 14.18.3, 16.x before 16.13.2, 17.x before 17.3.1 and is prone to an improper certificate validation vulnerability. A flaw is present in the application which fails to handle the URI SAN type when checking a certificate against a hostname. Successful exploitation allows an attacker to bypass name-constrained intermediates, and also Node.js could not match the URI correctly when a protocol allows URI SANs.
Platform: |
Microsoft Windows Server 2008 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows 8.1 |
Microsoft Windows Server 2012 R2 |
Microsoft Windows Server 2012 |
Microsoft Windows 7 |
Microsoft Windows 10 |
Microsoft Windows Server 2016 |
Microsoft Windows Server 2019 |
Microsoft Windows 11 |
Microsoft Windows Server 2022 |