Lucene search

K
cveHackeroneCVE-2023-46809
HistorySep 07, 2024 - 4:15 p.m.

CVE-2023-46809

2024-09-0716:15:02
CWE-385
hackerone
web.nvd.nist.gov
100
20
cve-2023-46809
security problem
reserved
nvd

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.5%

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.

Affected configurations

Vulners
Vulnrichment
Node
nodehttps\Match\/\/github.com\/nodejs\/node
OR
nodehttps\Match\/\/github.com\/nodejs\/node
OR
nodehttps\Match\/\/github.com\/nodejs\/node
VendorProductVersionCPE
nodehttps\//github.com/nodejs/nodecpe:2.3:a:node:https\:\/\/github.com\/nodejs\/node:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "vendor": "Node",
    "product": "https://github.com/nodejs/node",
    "versions": [
      {
        "version": "21.6.0",
        "status": "affected",
        "lessThanOrEqual": "21.6.0",
        "versionType": "semver"
      },
      {
        "version": "20.11.0",
        "status": "affected",
        "lessThanOrEqual": "20.11.0",
        "versionType": "semver"
      },
      {
        "version": "18.19.0",
        "status": "affected",
        "lessThanOrEqual": "18.19.0",
        "versionType": "semver"
      }
    ]
  }
]

Social References

More

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.5%