Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31600
HistoryAug 12, 2021 - 11:13 p.m.

Remote Code Execution (RCE)

2021-08-1223:13:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
139

0.008 Low

EPSS

Percentile

81.3%

Node.js was vulnerable to Remote Code Execution, XSS, application crashes due to missing input validation of host names returned by Domain Name Servers in the Node.js DNS library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.