Improper Authorization in Node.js - CVE-2020-8172
Published: June 3, 2020
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization process.
The
vulnerability exists due to TLS session reuse and host certificate
verification bypass, as the 'session' event can be emitted before the
'secureConnect' event in Node.js. The application agent performs https
session caching and an unauthorized connection can be established via
the cached session ticket and treated as authorized connection.
Affected software
MicroSCADA Pro SYS600
MicroSCADA X SYS600
Gateway Station (GWS)
FACTS Control Platform (FCP)
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
IBM Cloud Transformation Advisor
IBM Cloud Pak for Business Automation
nodejs (Alpine package)
nodejs-current (Alpine package)
rh-nodejs12-nodejs (Red Hat package)
How to mitigate CVE-2020-8172
MicroSCADA Pro SYS600 - update to 10.3
MicroSCADA X SYS600 - update to 10.3
nodejs (Alpine package) - update to 12.18.3-r0
nodejs-current (Alpine package) - update to 14.4.0-r0
IBM Cloud Pak for Business Automation - update to 20.0.2 ifix 001
rh-nodejs12-nodejs (Red Hat package) - update to 12.18.2-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Improper Authorization in nodejs (Alpine package)
- Improper Authorization in nodejs-current (Alpine package)
- Gentoo update for NodeJS
- Multiple vulnerabilities in Hitachi Energy MicroSCADA Pro/X SYS600
- Multiple vulnerabilities in Hitachi Energy FACTS Control Platform (FCP)
- Multiple vulnerabilities in Hitachi Energy Gateway Station (GWS)
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Multiple vulnerabilities in IBM Cloud Pak for Automation