CVE-2020-8252

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.

References

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00011.html

http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00023.html

https://hackerone.com/reports/965914

https://lists.fedoraproject.org/archives/list/[email protected]/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/

https://nodejs.org/en/blog/vulnerability/september-2020-security-releases/

https://security.gentoo.org/glsa/202009-15

https://security.netapp.com/advisory/ntap-20201009-0004/

https://usn.ubuntu.com/4548-1/

Details

Source: MITRE

Published: 2020-09-18

Updated: 2020-12-13

Type: CWE-120

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Tenable Plugins

View all (21 total)

IDNameProductFamilySeverity
146802CentOS 8 : nodejs:10 (CESA-2021:0548)NessusCentOS Local Security Checks
high
146638Oracle Linux 8 : nodejs:10 (ELSA-2021-0548)NessusOracle Linux Local Security Checks
high
146547RHEL 8 : nodejs:10 (RHSA-2021:0548)NessusRed Hat Local Security Checks
high
145813CentOS 8 : nodejs:12 (CESA-2020:4272)NessusCentOS Local Security Checks
high
144124Fedora 33 : 1:nodejs (2020-43d5a372fc)NessusFedora Local Security Checks
high
143819SUSE SLES12 Security Update : nodejs10 (SUSE-SU-2020:2823-1)NessusSuSE Local Security Checks
high
143665SUSE SLES12 Security Update : nodejs12 (SUSE-SU-2020:2812-1)NessusSuSE Local Security Checks
high
143663SUSE SLES15 Security Update : nodejs12 (SUSE-SU-2020:2813-1)NessusSuSE Local Security Checks
high
143657SUSE SLES15 Security Update : nodejs10 (SUSE-SU-2020:2829-1)NessusSuSE Local Security Checks
high
142450RHEL 8 : nodejs:12 (RHSA-2020:4903)NessusRed Hat Local Security Checks
high
141637Oracle Linux 8 : nodejs:12 (ELSA-2020-4272)NessusOracle Linux Local Security Checks
high
141536RHEL 8 : nodejs:12 (RHSA-2020:4272)NessusRed Hat Local Security Checks
high
141481Photon OS 3.0: Nodejs PHSA-2020-3.0-0150NessusPhotonOS Local Security Checks
high
141476Photon OS 1.0: Nodejs10 PHSA-2020-1.0-0331NessusPhotonOS Local Security Checks
high
141443Photon OS 2.0: Nodejs PHSA-2020-2.0-0288NessusPhotonOS Local Security Checks
high
141411openSUSE Security Update : nodejs10 (openSUSE-2020-1660)NessusSuSE Local Security Checks
high
141276openSUSE Security Update : nodejs12 (openSUSE-2020-1616)NessusSuSE Local Security Checks
high
141065GLSA-202009-15 : libuv: Buffer overflowNessusGentoo Local Security Checks
high
140924Ubuntu 20.04 LTS : libuv vulnerability (USN-4548-1)NessusUbuntu Local Security Checks
high
140795Node.js Multiple Vulnerabilities (September 2020 Security Releases)NessusMisc.
high
140627FreeBSD : Node.js -- September 2020 Security Releases (4ca5894c-f7f1-11ea-8ff8-0022489ad614)NessusFreeBSD Local Security Checks
high