PT-2022-5492 · Node.Js+9 · Node.Js+9

Haxatron1

·

Published

2022-11-04

·

Updated

2026-05-18

·

CVE-2022-43548

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions prior to 14.21.1 Node.js versions prior to 16.18.1 Node.js versions prior to 18.12.1 Node.js versions prior to 19.0.1
Description A OS Command Injection vulnerability exists in Node.js due to an insufficient IsAllowedHost check that can easily be bypassed, allowing rebinding attacks. The issue is related to the --inspect parameter and errors in converting octal IP addresses. This can allow a remote attacker to execute arbitrary code. The estimated number of potentially affected devices worldwide is not available.
Recommendations For versions prior to 14.21.1, update to version 14.21.1 or later. For versions prior to 16.18.1, update to version 16.18.1 or later. For versions prior to 18.12.1, update to version 18.12.1 or later. For versions prior to 19.0.1, update to version 19.0.1 or later. As a temporary workaround, consider disabling the --inspect parameter until a patch is available. Restrict access to the --inspect feature to minimize the risk of exploitation. Avoid using invalid octal IP addresses in the --inspect parameter until the issue is resolved.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:8832
ALSA-2022:8833
ALSA-2022:9073
ALSA-2023:0050
ALSA-2023:0321
ALT-PU-2022-3200
ALT-PU-2022-3235
ALT-PU-2022-3239
ALT-PU-2023-1461
AZL-11577
BDU:2022-06821
BIT-NODE-2022-43548
BIT-NODE-MIN-2022-43548
CESA-2022_8833
CESA-2022_9073
CESA-2023_0050
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2022-43548
DLA-3344-1
DSA-5326-1
MGASA-2022-0422
OESA-2022-2114
OPENSUSE-SU-2022_4003-1
OPENSUSE-SU-2022_4084-1
OPENSUSE-SU-2022_4254-1
OPENSUSE-SU-2022_4255-1
OPENSUSE-SU-2022_4301-1
OPENSUSE-SU-2023_0419-1
OPENSUSE-SU-2024:12488-1
OPENSUSE-SU-2024:12489-1
OPENSUSE-SU-2024:12554-1
RHSA-2022:8832
RHSA-2022:8833
RHSA-2022:9073
RHSA-2022_8832
RHSA-2022_8833
RHSA-2022_9073
RHSA-2023:0050
RHSA-2023:0321
RHSA-2023:0612
RHSA-2023:1533
RHSA-2023:1742
RHSA-2023_0050
RHSA-2023_0321
RLSA-2022:8832
RLSA-2022:8833
RLSA-2022:9073
RLSA-2023:0050
RLSA-2023:0321
SUSE-SU-2022:3967-1
SUSE-SU-2022:3968-1
SUSE-SU-2022:3989-1
SUSE-SU-2022:4003-1
SUSE-SU-2022:4084-1
SUSE-SU-2022:4254-1
SUSE-SU-2022:4255-1
SUSE-SU-2022:4301-1
SUSE-SU-2022_3967-1
SUSE-SU-2022_3968-1
SUSE-SU-2022_3989-1
SUSE-SU-2022_4003-1
SUSE-SU-2022_4084-1
SUSE-SU-2022_4254-1
SUSE-SU-2022_4255-1
SUSE-SU-2022_4301-1
SUSE-SU-2023:0408-1
SUSE-SU-2023:0419-1
USN-6491-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Node.Js
Red Hat
Rocky Linux
Suse
Ubuntu