CVE-2021-22884
published 2021-03-03CVE-2021-22884: Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not…
PriorityP357high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
32.36%
98.1th percentile
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | < nodejs 12.21.0~dfsg-1 (bookworm) | nodejs 12.21.0~dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| nodejs | node.js | >= 10.0.0 < 10.24.0 | 10.24.0 |
| nodejs | node.js | >= 12.0.0 < 12.21.0 | 12.21.0 |
| nodejs | node.js | >= 14.0.0 < 14.16.0 | 14.16.0 |
| nodejs | node.js | >= 15.0.0 < 15.10.0 | 15.10.0 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 12.21.0~dfsg-1 | 12.21.0~dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.2 | 10.19.0~dfsg-3ubuntu1.2 |
| nodejs | nodejs | >= 0 < 8.10.0~dfsg-2ubuntu0.4+esm3 | 8.10.0~dfsg-2ubuntu0.4+esm3 |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| oracle | mysql_cluster | <= 8.0.25 | — |
| oracle | nosql_database | < 20.3 | 20.3 |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | 1.0.1.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_oracle8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-10-05·CVSS 7.5
CVE-2021-22883 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to cause a denial of
service. This issue was only fixed in Ubuntu 20.04 LTS. (CVE-2021-22883)
Vít Šesták discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-22884)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nodejs: DNS rebinding in --inspect via invalid IP addresses
vendor_redhat·2022-07-08·CVSS 7.5
CVE-2022-32212 [HIGH] CWE-703 nodejs: DNS rebinding in --inspect via invalid IP addresses
nodejs: DNS rebinding in --inspect via invalid IP addresses
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
A vulnerability was found in NodeJS, where the IsAllowedHost check can be easily bypassed because IsIPAddress does not properly check if an IP address is invalid or not. When an invalid IPv4 address is provided (for instance, 10.0.2.555 is provided), browsers (such as Firefox) will make DNS requests to the DNS server. This issue provides a vector for an attacker-controlled DNS server or a Man-in-the-middle attack (MITM) who can spoof DNS respon
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) — CVE-2021-22884
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2021-22884 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) — CVE-2021-22884
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) vulnerability
CVE: CVE-2021-22884
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2021-22884
vendor_oracle·2021-07-15·CVSS 8.8
CVE-2021-22884 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2021-22884
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) vulnerability
CVE: CVE-2021-22884
CVSS: 8.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
nodejs: DNS rebinding in --inspect
vendor_redhat·2021-02-18·CVSS 8.8
CVE-2021-22884 [HIGH] CWE-20 nodejs: DNS rebinding in --inspect
nodejs: DNS rebinding in --inspect
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
A flaw was found in nodejs. A denial of service is possible when the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS over the network. If the attack
Debian
CVE-2021-22884: nodejs - Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebin...
vendor_debian·2021·CVSS 8.8
CVE-2021-22884 [HIGH] CVE-2021-22884: nodejs - Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebin...
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
Scope: local
bookworm: resolved (fixed in 12.21.0~dfsg-1)
bullseye: resolved (fixed in 12.21.0~dfsg-1)
forky: resolved (fixed in 12.21.0~dfsg-1)
sid: resolved (fixed in 12.21.0~dfsg-1)
trixie: resolved (fixed in 12.21.0~dfsg-1)
OSV
nodejs vulnerabilities
osv·2023-10-05·CVSS 7.5
CVE-2021-22883 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly use this issue to cause a denial of
service. This issue was only fixed in Ubuntu 20.04 LTS. (CVE-2021-22883)
Vít Šesták discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2021-22884)
GHSA
Node.js bad
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2021-22884 [HIGH] CWE-506 Node.js bad
Node.js bad
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
OSV
CVE-2021-22884: Node
osv·2021-03-03·CVSS 8.8
CVE-2021-22884 [HIGH] CVE-2021-22884: Node
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1069487https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/#node-js-inspector-dns-rebinding-vulnerability-cve-2018-7160https://security.netapp.com/advisory/ntap-20210416-0001/https://security.netapp.com/advisory/ntap-20210723-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1069487https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/#node-js-inspector-dns-rebinding-vulnerability-cve-2018-7160https://security.netapp.com/advisory/ntap-20210416-0001/https://security.netapp.com/advisory/ntap-20210723-0001/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-03-03
Published