cbcvebase.
CVE-2018-12123
published 2018-11-28

CVE-2018-12123: Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is…

medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.

Affected

14 ranges
VendorProductVersion rangeFixed in
debiannodejs< nodejs 10.15.0~dfsg-6 (bookworm)nodejs 10.15.0~dfsg-6 (bookworm)
msrccm1_nodejs_14.17.2-1_on_cbl_mariner_1.0
nodejsnode.js>= 10.0.0 < 10.14.010.14.0
nodejsnode.js>= 11.0.0 < 11.3.011.3.0
nodejsnode.js>= 6.0.0 < 6.15.06.15.0
nodejsnode.js>= 8.0.0 < 8.14.08.14.0
nodejsnodejs>= 0 < 10.15.0~dfsg-610.15.0~dfsg-6
nodejsnodejs>= 0 < 10.15.0~dfsg-610.15.0~dfsg-6
nodejsnodejs>= 0 < 10.15.0~dfsg-610.15.0~dfsg-6
nodejsnodejs>= 0 < 10.15.0~dfsg-610.15.0~dfsg-6
nodejsnodejs>= 0 < 0.10.25~dfsg2-2ubuntu1.2+esm10.10.25~dfsg2-2ubuntu1.2+esm1
nodejsnodejs>= 0 < 4.2.6~dfsg-1ubuntu4.2+esm14.2.6~dfsg-1ubuntu4.2+esm1
nodejsnodejs>= 0 < 8.10.0~dfsg-2ubuntu0.4+esm18.10.0~dfsg-2ubuntu0.4+esm1
the_node.js_projectnode.js

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv5.9MEDIUM