CVE-2020-13110

Source
https://cve.org/CVERecord?id=CVE-2020-13110
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-13110.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-13110
Aliases
Published
2020-05-16T12:15:12.140Z
Modified
2025-11-14T10:12:42.539264Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.

References

Affected packages

Git / github.com/mongodb-js/kerberos

Affected ranges

Type
GIT
Repo
https://github.com/mongodb-js/kerberos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

V0.*
V0.0.10
V0.0.11
V0.0.12
V0.0.13
V0.0.14
V0.0.15
V0.0.16
V0.0.17
V0.0.18
V0.0.19
V0.0.20
V0.0.21
V0.0.22
V0.0.23
V0.0.4
V0.0.5
V0.0.6
V0.0.7
V0.0.8
V0.0.9
v0.*
v0.0.24

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-13110.json"