CVE-2019-15604

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate
References
Link Resource
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/746733 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Patch Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html Mailing List Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0573 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0579 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0597 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0598 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0602 Third Party Advisory
https://hackerone.com/reports/746733 Exploit Third Party Advisory
https://nodejs.org/en/blog/release/v10.19.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v12.15.0/ Release Notes Vendor Advisory
https://nodejs.org/en/blog/release/v13.8.0/ Vendor Advisory
https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ Vendor Advisory
https://security.gentoo.org/glsa/202003-48 Third Party Advisory
https://security.netapp.com/advisory/ntap-20200221-0004/ Third Party Advisory
https://www.debian.org/security/2020/dsa-4669 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html Patch Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Patch Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:-:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:graalvm:19.3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:oracle:graalvm:20.0.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 04:29

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00008.html - Mailing List, Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0573 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0573 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0579 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0579 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0597 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0597 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0598 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0598 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2020:0602 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2020:0602 - Third Party Advisory
References () https://hackerone.com/reports/746733 - Exploit, Third Party Advisory () https://hackerone.com/reports/746733 - Exploit, Third Party Advisory
References () https://nodejs.org/en/blog/release/v10.19.0/ - Release Notes, Vendor Advisory () https://nodejs.org/en/blog/release/v10.19.0/ - Release Notes, Vendor Advisory
References () https://nodejs.org/en/blog/release/v12.15.0/ - Release Notes, Vendor Advisory () https://nodejs.org/en/blog/release/v12.15.0/ - Release Notes, Vendor Advisory
References () https://nodejs.org/en/blog/release/v13.8.0/ - Vendor Advisory () https://nodejs.org/en/blog/release/v13.8.0/ - Vendor Advisory
References () https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ - Vendor Advisory () https://nodejs.org/en/blog/vulnerability/february-2020-security-releases/ - Vendor Advisory
References () https://security.gentoo.org/glsa/202003-48 - Third Party Advisory () https://security.gentoo.org/glsa/202003-48 - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20200221-0004/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20200221-0004/ - Third Party Advisory
References () https://www.debian.org/security/2020/dsa-4669 - Third Party Advisory () https://www.debian.org/security/2020/dsa-4669 - Third Party Advisory
References () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory () https://www.oracle.com//security-alerts/cpujul2021.html - Patch, Third Party Advisory
References () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory () https://www.oracle.com/security-alerts/cpuapr2020.html - Patch, Third Party Advisory

07 Mar 2024, 21:24

Type Values Removed Values Added
CPE cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

Information

Published : 2020-02-07 15:15

Updated : 2024-11-21 04:29


NVD link : CVE-2019-15604

Mitre link : CVE-2019-15604

CVE.ORG link : CVE-2019-15604


JSON object : View

Products Affected

redhat

  • enterprise_linux
  • enterprise_linux_server_aus
  • enterprise_linux_server_tus
  • software_collections
  • enterprise_linux_eus

nodejs

  • node.js

oracle

  • graalvm
  • communications_cloud_native_core_network_function_cloud_native_environment

debian

  • debian_linux

opensuse

  • leap
CWE
CWE-295

Improper Certificate Validation