Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-22931

Опубликовано: 16 авг. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

18.13.0+dfsg1-1ubuntu2
esm-apps/bionic

not-affected

8.10.0~dfsg-2ubuntu0.4+esm2
esm-apps/focal

not-affected

10.19.0~dfsg-3ubuntu1.1
esm-apps/jammy

not-affected

12.22.9~dfsg-1ubuntu3
esm-apps/xenial

not-affected

4.2.6~dfsg-1ubuntu4.2+esm2
esm-infra-legacy/trusty

not-affected

0.10.25~dfsg2-2ubuntu1.2+esm1
focal

not-affected

10.19.0~dfsg-3ubuntu1.1
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

EPSS

Процентиль: 72%
0.00738
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
почти 4 года назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
nvd
почти 4 года назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS3: 9.8
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 4 года назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Co ...

CVSS3: 9.8
github
около 3 лет назад

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

EPSS

Процентиль: 72%
0.00738
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3