CVE-2023-23919
Vulnerability Summary
Timeline
Description
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn could be used to cause a denial of service.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.32%• Percentile: 55%
Techniques & Countermeasures
- CWE-310•Cryptographic Issues
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Affected Systems
- nodejs•node
≥ 4.0, < 4.* | ≥ 5.0, < 5.* | ≥ 6.0, < 6.* | ≥ 7.0, < 7.* | ≥ 8.0, < 8.* | ≥ 9.0, < 9.* | ≥ 10.0, < 10.* | ≥ 11.0, < 11.* | ≥ 12.0, < 12.* | ≥ 13.0, < 13.* | ≥ 14.0, < 14.21.3 | ≥ 15.0, < 15.* | ≥ 16.0, < 16.19.1 | ≥ 17.0, < 17.* | ≥ 18.0, < 18.14.1 | ≥ 19.0, < 19.2.0
- nodejs•node.js
≥ 14.0.0, ≤ 14.14.0 | ≥ 14.0.0, < 14.21.3 | ≥ 16.0.0, ≤ 16.12.0 | ≥ 16.0.0, < 16.19.1 | ≥ 18.0.0, ≤ 18.11.0 | ≥ 18.0.0, < 18.14.1 | ≥ 19.0.0, < 19.2.0