Lucene search

K
cvelistNodejsCVELIST:CVE-2018-7160
HistoryMar 21, 2018 - 12:00 a.m.

CVE-2018-7160

2018-03-2100:00:00
CWE-350
nodejs
www.cve.org
1

8.4 High

AI Score

Confidence

High

0.033 Low

EPSS

Percentile

91.3%

The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.

CNA Affected

[
  {
    "product": "Node.js",
    "vendor": "The Node.js Project",
    "versions": [
      {
        "status": "affected",
        "version": "^6.0.0 || ^8.0.0 || ^9.0.0"
      }
    ]
  }
]