Back to search
CVE-2020-8252
Published: Sep 18, 2020
Modified: Apr 30, 2025
PUBLISHED
Description
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
| Vendor | Product | Versions |
|---|---|---|
NodeJS | Node | affected 4.0 - < 4.*affected 5.0 - < 5.*affected 6.0 - < 6.*affected 7.0 - < 7.*affected 8.0 - < 8.*+6 more versions |
Weaknesses (CWE)
References
https://hackerone.com/reports/965914
x_refsource_MISC
GLSA-202009-15
vendor-advisory
x_refsource_GENTOO
USN-4548-1
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2020:1616
vendor-advisory
x_refsource_SUSE
https://security.netapp.com/advisory/ntap-20201009-0004/
x_refsource_CONFIRM
openSUSE-SU-2020:1660
vendor-advisory
x_refsource_SUSE
FEDORA-2020-43d5a372fc
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now