[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-43548Date: (C)2022-11-22   (M)2024-04-19


A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.1CVSS Score :
Exploit Score: 2.2Exploit Score:
Impact Score: 5.9Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector:
Attack Complexity: HIGHAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: HIGHAvailability:
Integrity: HIGH 
Availability: HIGH 
  
Reference:
DSA-5326
https://lists.debian.org/debian-lts-announce/2023/02/msg00038.html
https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/
https://security.netapp.com/advisory/ntap-20230120-0004/
https://security.netapp.com/advisory/ntap-20230427-0007/

CWE    1
CWE-78
OVAL    37
oval:org.secpod.oval:def:5800022
oval:org.secpod.oval:def:3300846
oval:org.secpod.oval:def:19500180
oval:org.secpod.oval:def:3300687
...

© SecPod Technologies