CVE-2020-14967 is a critical vulnerability affecting the jsrsasign package (versions prior to 8.0.18) for Node.js, as well as related NetApp products. It stems from an RSA PKCS1 v1.5 decryption flaw that fails to detect ciphertext modification, specifically the prepending of null bytes. This allows an attacker to potentially trigger memory corruption issues. With a CVSS score of 9.8, this vulnerability is highly severe, requiring no user interaction or privileges, and can lead to complete compromise of confidentiality, integrity, and availability. Despite its critical severity, there is currently no public exploit code (Metasploit, Nuclei, ExploitDB) or evidence of active exploitation, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0.18CPE matchmatch criteria | cpe:2.3:a:kjur:jsrsasign:*:*:*:*:*:node.js:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:max_data:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.