CVE-2022-32212 — Improper Access Control in Node
Severity
8.1HIGHNVD
EPSS
0.1%
top 80.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 14
Latest updateNov 21
Description
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9
Affected Packages5 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36, 37
🔴Vulnerability Details
4📋Vendor Advisories
6Oracle▶
Oracle Oracle Communications Applications Risk Matrix: User Interface (Node.js) — CVE-2022-32212↗2023-01-15
Microsoft▶
A OS Command Injection vulnerability exists in Node.js versions <14.20.0 <16.20.0 <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly c↗2022-07-12