Lucene search

K
cvelistHackeroneCVELIST:CVE-2022-32212
HistoryJul 14, 2022 - 12:00 a.m.

CVE-2022-32212

2022-07-1400:00:00
CWE-284
hackerone
www.cve.org
1

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.1%

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "https://github.com/nodejs/node",
    "versions": [
      {
        "version": "Fixed in 14.20.1+, 16.17.1+,18.9.1+",
        "status": "affected"
      }
    ]
  }
]