PT-2021-2514 · Node.Js+8 · Node.Js+8

Published

2020-01-24

·

Updated

2024-12-16

·

CVE-2021-22884

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions prior to 10.24.0 Node.js versions prior to 12.21.0 Node.js versions prior to 14.16.0 Node.js versions prior to 15.10.0
Description The issue is related to the presence of localhost6 in the whitelist, which can be exploited by a remote attacker to gain access to confidential data, compromise data integrity, and cause a denial of service. The localhost6 domain can be used to bypass DNS rebinding protection if it is not present in the /etc/hosts file, allowing an attacker who controls the victim's DNS server or can spoof its responses to apply the attack.
Recommendations For versions prior to 10.24.0, update to version 10.24.0 or later. For versions prior to 12.21.0, update to version 12.21.0 or later. For versions prior to 14.16.0, update to version 14.16.0 or later. For versions prior to 15.10.0, update to version 15.10.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:0734
ALSA-2021:0735
ALSA-2021:0744
ALT-PU-2020-1090
ALT-PU-2021-1397
ALT-PU-2021-1493
ALT-PU-2022-3073
BDU:2021-01895
BIT-NODE-2021-22884
BIT-NODE-MIN-2021-22884
CESA-2021_0734
CESA-2021_0735
CESA-2021_0744
CVE-2021-22884
DSA-4863-1
MGASA-2021-0092
OESA-2021-1114
OPENSUSE-SU-2021:0356-1
OPENSUSE-SU-2021:0357-1
OPENSUSE-SU-2021:0372-1
OPENSUSE-SU-2021:0389-1
OPENSUSE-SU-2021_0356-1
OPENSUSE-SU-2021_0357-1
OPENSUSE-SU-2021_0372-1
OPENSUSE-SU-2021_0389-1
OPENSUSE-SU-2024:11096-1
RHSA-2021:0734
RHSA-2021:0735
RHSA-2021:0738
RHSA-2021:0739
RHSA-2021:0740
RHSA-2021:0741
RHSA-2021:0744
RHSA-2021:0827
RHSA-2021:0830
RHSA-2021:0831
RHSA-2021_0734
RHSA-2021_0735
RHSA-2021_0744
RLSA-2021:0734
RLSA-2021:0735
RLSA-2021:0744
SUSE-SU-2021:0648-1
SUSE-SU-2021:0649-1
SUSE-SU-2021:0650-1
SUSE-SU-2021:0651-1
SUSE-SU-2021:0673-1
SUSE-SU-2021:0674-1
SUSE-SU-2021:0686-1
SUSE-SU-2021:2620-1
SUSE-SU-2021_0686-1
USN-6418-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu