CVE-2018-12120
published 2018-11-28CVE-2018-12120: Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
4.28%
90.1th percentile
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
Affected
71 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 8.9.3~dfsg-5 (bookworm) | nodejs 8.9.3~dfsg-5 (bookworm) |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | — | — |
| f5 | big-ip_access_policy_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_access_policy_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | — | — |
| f5 | big-ip_advanced_firewall_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_analytics | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_apm | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | — | — |
| f5 | big-ip_application_acceleration_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_application_acceleration_manager | 13.0.0 – 13.1.2 | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | — | — |
| f5 | big-ip_application_security_manager | 12.1.3 – 12.1.4 | — |
| f5 | big-ip_application_security_manager | 13.0.0 – 13.1.2 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
vendor_f5·2019-09-04·CVSS 9.4
CVE-2019-6644 [HIGH] CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
CVE-2019-6644: Similar to the issue identified in CVE-2018-12120, on versions 14
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP Analytics, BIG-IP DNS, BIG-IP Edge Gateway, BIG-IP FPS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP WebAccelerator
Affected Versions: 12.1.3 - 12.1.4; 13.0.0 - 13.1.2; 14.0.0; 14.1.0
F5 Advisory Articles: K75532331
F5 References: https://support.f5.com/csp/article/K75532331
Red Hat
nodejs: Debugger port 5858 listens on any interface by default
vendor_redhat·2018-11-27·CVSS 8.1
CVE-2018-12120 [HIGH] CWE-284 nodejs: Debugger port 5858 listens on any interface by default
nodejs: Debugger port 5858 listens on any interface by default
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
Statement: The nodejs RPMs shipped in Red Hat OpenShift Container Platform (OCP) versions 3.6 through 3.10 are vulnerable to this flaw because they c
Debian
CVE-2018-12120: nodejs - Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any...
vendor_debian·2018·CVSS 8.1
CVE-2018-12120 [HIGH] CVE-2018-12120: nodejs - Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any...
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
Scope: local
bookworm: resolved (fixed in 8.9.3~dfsg-5)
bullseye: resolved (fixed in 8.9.3~dfsg-5)
forky: resolved (fixed in 8.9.3~dfsg-5)
sid: resolved (fixed in 8.9.3~dfsg-5)
trixie: resolved (fixed in 8.9.3~dfsg
GHSA
GHSA-jr9w-mmvc-9gp2: Similar to the issue identified in CVE-2018-12120, on versions 14
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2019-6644 [HIGH] GHSA-jr9w-mmvc-9gp2: Similar to the issue identified in CVE-2018-12120, on versions 14
Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1.0-12.1.4 BIG-IP will bind a debug nodejs process to all interfaces when invoked. This may expose the process to unauthorized users if the plugin is left in debug mode and the port is accessible.
GHSA
GHSA-8fqw-43x4-4q75: Node
ghsa_unreviewed·2022-05-13
CVE-2018-12120 [HIGH] CWE-829 GHSA-8fqw-43x4-4q75: Node
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
OSV
CVE-2018-12120: Node
osv·2018-11-28·CVSS 8.1
CVE-2018-12120 [HIGH] CVE-2018-12120: Node
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [epel-all]
bugzilla·2018-12-19·CVSS 8.1
CVE-2018-12120 [HIGH] CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [epel-all]
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [fedora-all]
bugzilla·2018-12-19·CVSS 8.1
CVE-2018-12120 [HIGH] CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [fedora-all]
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default
bugzilla·2018-12-19·CVSS 8.1
CVE-2018-12120 [HIGH] CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default
CVE-2018-12120 nodejs: Debugger port 5858 listens on any interface by default
A flaw was found in Node.js versions before 6.15.0. A Debugger port 5858 listens on any interface by default. When the debugger is enabled with `node --debug` or `node debug`, it listens to port 5858 on all interfaces by default. This may allow remote computers to attach to the debug port and evaluate arbitrary JavaScript. The default interface is now localhost. It has always been possible to start the debugger on a specific interface, such as `node --debug=localhost`. The debugger was removed in Node.js 8 and replaced with the inspector, so no versions from 8 and later are vulnerable.
References:
https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
Discussion:
Created nodejs tracking bu
2018-11-28
Published