CVE-2020-8174

Name
CVE-2020-8174
Description
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://hackerone.com/reports/784186
MISC https://www.oracle.com/security-alerts/cpuoct2020.html
CONFIRM https://security.netapp.com/advisory/ntap-20201023-0003/
GENTOO https://security.gentoo.org/glsa/202101-07
MISC https://www.oracle.com/security-alerts/cpujan2021.html
Patch https://www.oracle.com//security-alerts/cpujul2021.html
MISC https://www.oracle.com/security-alerts/cpuapr2022.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* node.js >= None < 10.21.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* node.js >= 12.0.0 < 12.18.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* node.js >= 14.0.0 < 14.4.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= None < 10.21.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 12.0.0 < 12.18.0
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* nodejs >= 14.0.0 < 14.4.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status