CVE-2022-43548
published 2022-12-05CVE-2022-43548: A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can…
PriorityP357high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
14.02%
96.1th percentile
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nodejs | < nodejs 18.12.1+dfsg-1 (bookworm) | nodejs 18.12.1+dfsg-1 (bookworm) |
| msrc | cbl2_nodejs_16.18.1-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_nodejs_14.21.1-1_on_cbl_mariner_1.0 | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | — | — |
| nodejs | node.js | 14.0.0 – 14.14.0 | — |
| nodejs | node.js | >= 14.15.0 < 14.21.1 | 14.21.1 |
| nodejs | node.js | 16.0.0 – 16.12.0 | — |
| nodejs | node.js | >= 16.13.0 < 16.18.1 | 16.18.1 |
| nodejs | node.js | 18.0.0 – 18.11.0 | — |
| nodejs | nodejs | >= 0 < 12.22.12~dfsg-1~deb11u3 | 12.22.12~dfsg-1~deb11u3 |
| nodejs | nodejs | >= 0 < 18.12.1+dfsg-1 | 18.12.1+dfsg-1 |
| nodejs | nodejs | >= 0 < 18.12.1+dfsg-1 | 18.12.1+dfsg-1 |
| nodejs | nodejs | >= 0 < 18.12.1+dfsg-1 | 18.12.1+dfsg-1 |
| nodejs | nodejs | >= 0 < 10.19.0~dfsg-3ubuntu1.3 | 10.19.0~dfsg-3ubuntu1.3 |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1ubuntu3.2 | 12.22.9~dfsg-1ubuntu3.2 |
| nodejs | nodejs | >= 0 < 8.10.0~dfsg-2ubuntu0.4+esm4 | 8.10.0~dfsg-2ubuntu0.4+esm4 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-11-21·CVSS 8.1
CVE-2022-32213 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
Axel Chong discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-32212)
Zeyu Zhang discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-32213,
CVE-2022-32214, CVE-2022-32215)
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening
Oracle
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) — CVE-2022-43548
vendor_oracle·2023-07-15·CVSS 8.1
CVE-2022-43548 [HIGH] Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) — CVE-2022-43548
Oracle Oracle JD Edwards Risk Matrix: E1 Dev Platform Tech (Node.js) vulnerability
CVE: CVE-2022-43548
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2022-43548
vendor_oracle·2023-04-15·CVSS 8.1
CVE-2022-43548 [HIGH] Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) — CVE-2022-43548
Oracle Oracle MySQL Risk Matrix: Cluster: JS module (Node.js) vulnerability
CVE: CVE-2022-43548
CVSS: 8.1
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2022-43548
vendor_oracle·2023-01-15·CVSS 8.1
CVE-2022-43548 [HIGH] Oracle Oracle Java SE Risk Matrix: Node (Node.js) — CVE-2022-43548
Oracle Oracle Java SE Risk Matrix: Node (Node.js) vulnerability
CVE: CVE-2022-43548
CVSS: 8.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Microsoft
A OS Command Injection vulnerability exists in Node.js versions <14.21.1 <16.18.1 <18.12.1 <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not p
vendor_msrc·2022-12-13·CVSS 8.1
CVE-2022-43548 [HIGH] CWE-78 A OS Command Injection vulnerability exists in Node.js versions <14.21.1 <16.18.1 <18.12.1 <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not p
A OS Command Injection vulnerability exists in Node.js versions Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: htt
Red Hat
nodejs: DNS rebinding in inspect via invalid octal IP address
vendor_redhat·2022-11-04·CVSS 8.1
CVE-2022-43548 [HIGH] CWE-350 nodejs: DNS rebinding in inspect via invalid octal IP address
nodejs: DNS rebinding in inspect via invalid octal IP address
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
A flaw was found in NodeJS. The issue occurs in the Node.js rebinding protector for --inspect that still allows invalid IP addresses, specifically, the octal format. This flaw allows an attacker to perform DNS rebinding and execute arbitrary code.
Statement: Redhat has marked this vulnerabil
Debian
CVE-2022-43548: nodejs - A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18...
vendor_debian·2022·CVSS 8.1
CVE-2022-43548 [HIGH] CVE-2022-43548: nodejs - A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18...
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
Scope: local
bookworm: resolved (fixed in 18.12.1+dfsg-1)
bullseye: resolved (fixed in 12.22.12~dfsg-1~deb11u3)
forky: resolved (fixed in 18.12.1+dfsg-1)
sid: resolved (fixed in 18.12.1+dfsg-1)
trixie: resolved (fixed in 18.12.1+dfsg-1)
OSV
nodejs vulnerabilities
osv·2023-11-21·CVSS 8.1
CVE-2022-32212 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
Axel Chong discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-32212)
Zeyu Zhang discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-32213,
CVE-2022-32214, CVE-2022-32215)
It was discovered that Node.js incorrectly handled certain inputs. If a user
or an automated system were tricked into opening a specially crafted input
file, a remote attacker could possibly
GHSA
GHSA-r934-m2c7-26gh: A OS Command Injection vulnerability exists in Node
ghsa_unreviewed·2022-12-06·CVSS 8.1
CVE-2022-43548 [HIGH] CWE-78 GHSA-r934-m2c7-26gh: A OS Command Injection vulnerability exists in Node
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
OSV
CVE-2022-43548: A OS Command Injection vulnerability exists in Node
osv·2022-12-05·CVSS 8.1
CVE-2022-43548 [HIGH] CVE-2022-43548: A OS Command Injection vulnerability exists in Node
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/02/msg00038.htmlhttps://nodejs.org/en/blog/vulnerability/november-2022-security-releases/https://security.netapp.com/advisory/ntap-20230120-0004/https://security.netapp.com/advisory/ntap-20230427-0007/https://www.debian.org/security/2023/dsa-5326https://lists.debian.org/debian-lts-announce/2023/02/msg00038.htmlhttps://nodejs.org/en/blog/vulnerability/november-2022-security-releases/https://security.netapp.com/advisory/ntap-20230120-0004/https://security.netapp.com/advisory/ntap-20230427-0007/https://www.debian.org/security/2023/dsa-5326
2022-12-05
Published