Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-32212
HistoryJul 14, 2022 - 3:15 p.m.

Command injection

2022-07-1415:15:00
PRIOn knowledge base
www.prio-n.com
9

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.1%

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.