CVE-2021-22931
published 2021-08-16CVE-2021-22931: Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
21.95%
97.4th percentile
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nodejs | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_nodejs_16.14.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-gevent_21.1.2-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_nodejs_14.17.5-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node | >= 10.0 < 10.* | 10.* |
| nodejs | node | >= 11.0 < 11.* | 11.* |
| nodejs | node | >= 12.0 < 12.22.5 | 12.22.5 |
| nodejs | node | >= 13.0 < 13.* | 13.* |
| nodejs | node | >= 14.0 < 14.17.5 | 14.17.5 |
| nodejs | node | >= 15.0 < 15.* | 15.* |
| nodejs | node | >= 16.0 < 16.6.2 | 16.6.2 |
| nodejs | node | >= 4.0 < 4.* | 4.* |
| nodejs | node | >= 5.0 < 5.* | 5.* |
| nodejs | node | >= 6.0 < 6.* | 6.* |
| nodejs | node | >= 7.0 < 7.* | 7.* |
| nodejs | node | >= 8.0 < 8.* | 8.* |
| nodejs | node | >= 9.0 < 9.* | 9.* |
| nodejs | node.js | 12.0.0 – 12.12.0 | — |
| nodejs | node.js | >= 12.13.0 < 12.22.5 | 12.22.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Target Node.js versions prior to 16.6.0, 14.17.4, and 12.22.4 — missing input validation of hostnames returned by DNS in the Node.js dns library enables RCE, XSS, and domain hijacking ↗
- →Exploitation vector is network/HTTP — monitor for anomalous DNS responses containing atypical/special characters in hostnames being processed by Node.js applications ↗
- →Exploitation can lead to domain hijacking and injection attacks; inspect DNS responses consumed by Node.js for hostnames with unexpected or non-standard characters ↗
- ·Red Hat Enterprise Linux 8 (nodejs:16/nodejs) and RHEL 9 (nodejs) are marked Not Affected; Red Hat Quay 3 (quay/quay-rhel8) is marked Will Not Fix with LOW impact because nodejs is only used at build time from RHEL 3.5 onward ↗
- ·Exploitation requires network access (HTTP protocol, remote exploit: Yes) per Oracle advisories; CVSS score is 9.8 critical ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa9.1CRITICAL
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7r9p-c88x-w357: Node
ghsa_unreviewed·2022-05-24
CVE-2021-22931 [CRITICAL] CWE-170 GHSA-7r9p-c88x-w357: Node
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
GHSA
Path Traversal in Apache James Server
ghsa·2022-02-08·CVSS 9.1
CVE-2022-22931 [CRITICAL] CWE-22 Path Traversal in Apache James Server
Path Traversal in Apache James Server
Apache James Server prior to version 3.6.2 contains a path traversal vulnerability. The fix for CVE-2021-40525 does not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the username being used).
OSV
CVE-2021-22931: Node
osv·2021-08-16·CVSS 9.8
CVE-2021-22931 [CRITICAL] CVE-2021-22931: Node
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Node.js) — CVE-2021-22931
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2021-22931 [CRITICAL] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Node.js) — CVE-2021-22931
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech - Cloud (Node.js) vulnerability
CVE: CVE-2021-22931
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Oracle
Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) — CVE-2021-22931
vendor_oracle·2022-01-15·CVSS 9.8
CVE-2021-22931 [CRITICAL] Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) — CVE-2021-22931
Oracle Oracle PeopleSoft Risk Matrix: Elastic Search (Node.js) vulnerability
CVE: CVE-2021-22931
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) — CVE-2021-22931
vendor_oracle·2021-10-15·CVSS 9.8
CVE-2021-22931 [CRITICAL] Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) — CVE-2021-22931
Oracle Oracle MySQL Risk Matrix: Cluster: General (Node.js) vulnerability
CVE: CVE-2021-22931
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
nodejs: Improper handling of untypical characters in domain names
vendor_redhat·2021-08-11·CVSS 9.8
CVE-2021-22931 [CRITICAL] CWE-20 nodejs: Improper handling of untypical characters in domain names
nodejs: Improper handling of untypical characters in domain names
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
A flaw was found in Node.js. These vulnerabilities include remote code execution, Cross-site scripting (XSS), application crashes due to missing input validation of hostnames returned by Domain Name Servers in the Node.js DNS library, which can lead to the output of wrong hostnames (leading to Domain hijacking) and injection vulnerabilities in applications using the library.
Stat
Microsoft
Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to Remote Code Execution XSS Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns li
vendor_msrc·2021-08-10·CVSS 9.8
CVE-2021-22931 [CRITICAL] CWE-20 Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to Remote Code Execution XSS Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns li
Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to Remote Code Execution XSS Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began
Debian
CVE-2021-22931: nodejs - Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Executi...
vendor_debian·2021·CVSS 9.8
CVE-2021-22931 [CRITICAL] CVE-2021-22931: nodejs - Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Executi...
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1178337https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/https://security.gentoo.org/glsa/202401-02https://security.netapp.com/advisory/ntap-20210923-0001/https://security.netapp.com/advisory/ntap-20211022-0003/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://hackerone.com/reports/1178337https://nodejs.org/en/blog/vulnerability/aug-2021-security-releases/https://security.gentoo.org/glsa/202401-02https://security.netapp.com/advisory/ntap-20210923-0001/https://security.netapp.com/advisory/ntap-20211022-0003/https://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-08-16
Published