CVE-2021-44532
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
24/02/2022
Last modified:
05/10/2022
Description
Node.js
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | 12.22.9 (excluding) | |
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | 14.0.0 (including) | 14.18.3 (excluding) |
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | 16.0.0 (including) | 16.13.2 (excluding) |
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | 17.0.0 (including) | 17.3.1 (excluding) |
cpe:2.3:a:oracle:graalvm:20.3.5:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:oracle:graalvm:21.3.1:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:oracle:graalvm:22.0.0.2:*:*:*:enterprise:*:*:* | ||
cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* | 8.0.29 (including) | |
cpe:2.3:a:oracle:mysql_connectors:*:*:*:*:*:*:*:* | 8.0.28 (including) | |
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* | 8.0.29 (including) | |
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | 5.7.37 (including) | |
cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.0.28 (including) |
cpe:2.3:a:oracle:mysql_workbench:*:*:*:*:*:*:*:* | 8.0.0 (including) | 8.0.28 (including) |
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* | ||
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://hackerone.com/reports/1429694
- https://nodejs.org/en/blog/vulnerability/jan-2022-security-releases/
- https://security.netapp.com/advisory/ntap-20220325-0007/
- https://www.debian.org/security/2022/dsa-5170
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html