Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36365
HistoryJul 15, 2022 - 10:43 a.m.

OS Command Injection

2022-07-1510:43:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
28
os command injection
node
isipaddress
inspector_socket.cc
dns rebinding
dbs requests

EPSS

0.001

Percentile

43.9%

node is vulnerable to OS Command Injection. The vulnerability exists due to the insufficient sanitizations in IsIPAddress function of inspector_socket.cc, which allows an attacker to gain control of the victim’s router by performing DNS rebinding attacks via DBS requests.

References