Lucene search

K
hackeroneZeyu2001H1:1714979
HistorySep 28, 2022 - 8:45 a.m.

Internet Bug Bounty: DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)

2022-09-2808:45:11
zeyu2001
hackerone.com
$4200
61
internet bug bounty
dns rebinding
cve-2022-32212
macos devices
node.js debugger
remote code execution

0.033 Low

EPSS

Percentile

91.3%

The fix for CVE-2022-32212, covered the cases for routable IP addresses, however, there exists a specific behavior on macOS devices when handling the http://0.0.0.0 URL that allows an attacker-controlled DNS server to bypass the DNS rebinding protection by resolving hosts in the .local domain.

Original HackerOne report

Node.js Blog

Impact

Attacker with access to a compromised DNS server or the ability to spoof its responses can gain access to the Node.js debugger, which can result in remote code execution.