V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2022-43548
AST
High

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost …

CVSS
7.5
High
EPSS
0.01
p67
Published
2022-01-01
Updated
2022-01-01
Description

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.

Tags · CWE
Pre-auth
CWE-350
CWE-78
CAPEC-6
CAPEC-15
CAPEC-43
CAPEC-73
CAPEC-88
CAPEC-89
CAPEC-108
CAPEC-142
CAPEC-275
Affected products
NodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsNodejsRh-nodejs14-nodejs
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.006 · p67
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-142 · CWE-350
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
nodejsTracked
rh-nodejs14-nodejsTracked
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities