VDB
CVE-2021-22884
CVE-2021-22884
PUBLISHED
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.
EPSS 0.27% · 50.6th percentile
Risk Scores
EPSS Score
0.27%
50.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | node-min | 12.0.0, 14.0.0, 15.0.0 |
| Bitnami | node | 15.0.0, 14.0.0, 15.0.0 |
| Bitnami | node-min | 15.0.0, 10.0.0, 12.0.0 |
| Bitnami | node | 10.0.0, 12.0.0, 15.0.0 |
Timeline
- CVE Published
- Feb 23, 2021 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 19, 2021 EPSS Score
- Jun 24, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 27, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf url
- https://hackerone.com/reports/1069487 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E4FRS5ZVK4ZQ7XIJQNGIKUXG2DJFHLO7/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F45Y7TXSU33MTKB6AGL2Q5V5ZOCNPKOG/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSYFUGKFUSZ27M5TEZ3FKILWTWFJTFAZ/ url
- https://nodejs.org/en/blog/vulnerability/february-2021-security-releases/ url
- https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/#node-js-inspector-dns-rebinding-vulnerability-cve-2018-7160 url
- https://security.netapp.com/advisory/ntap-20210416-0001/ url
- https://security.netapp.com/advisory/ntap-20210723-0001/ url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-22884 url