Mageni can help you to save time and money
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. Mageni is used by companies of all sizes. You will love Mageni's powerful features and ease of use. No registration or credit card is required.
Download Now
Node.js 12.x < 12.22.11, 14.x < 14.19.1, 16.x < 16.14.2, 17.x < 17.7.2 DoS Vulnerability - Windows
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
Node.js is prone to a denial of service (DoS) vulnerability in OpenSSL.
Insight
Insight
The following flaw exists in OpenSSL as used by Node.js: The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities parsing certification requests from subscribers - Anything else which parses ASN.1 elliptic curve parameters Also any other applications that use the BN_mod_sqrt() where the attacker can control the parameter values are vulnerable to this DoS issue. In the OpenSSL 1.0.2 version the public key is not parsed during initial parsing of the certificate which makes it slightly harder to trigger the infinite loop. However any operation which requires the public key from the certificate will trigger the infinite loop. In particular the attacker can use a self-signed certificate to trigger the loop during verification of the certificate signature.
Affected Software
Affected Software
Node.js version 12.x prior to 12.22.11, 14.x prior to 14.19.1, 16.x prior to 16.14.2 and 17.x prior to 17.7.2.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Update to version 12.22.11, 14.19.1, 16.14.2, 17.7.2 or later.
Common Vulnerabilities and Exposures (CVE)
References
Automate with a few clicks your vulnerability scanning, assessment and management process
Automate with a few clicks your vulnerability scanning, assessment and management process
Mageni automates for you the vulnerability scanning, assessment and management process saving you a ton of time, resources, and money. No registration or credit card is required. Mageni Community Edition is fast, powerful, free, and open-source. Download it now and Mageni will find your vulnerabilities before they are exploited by hackers.
1. Download Multipass
2. Launch a multipass instance
3. Install Mageni
1. If you don’t have it already, install Brew. Then, to install Multipass simply execute:
2. Launch a multipass instance
2. Install Mageni
1. Download the installer for Windows
2. Ensure your network is private
3. Run the installer
4. Launch a multipass instance
5. Log into the multipass instance
6. Install Mageni