{"id":"AZL-8819","summary":"CVE-2021-44533 affecting package nodejs for versions less than 16.14.0-1","details":"Node.js \u003c 12.22.9, \u003c 14.18.3, \u003c 16.13.2, and \u003c 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.","modified":"2026-04-01T05:23:35.793401Z","published":"2022-02-24T19:15:09Z","upstream":["CVE-2021-44533"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-44533"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Azure Linux:2","purl":"pkg:rpm/azure-linux/nodejs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.14.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-8819.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}