SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22931

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames…

CRITICAL 9.8EPSS 22.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 22.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
21.95% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-170, CWE-20
Affected
nodejs/node.js · netapp/active iq unified manager · netapp/nextgen api · netapp/oncommand insight · netapp/oncommand workflow automation · netapp/snapcenter · oracle/graalvm · oracle/mysql cluster · oracle/peoplesoft enterprise peopletools · siemens/sinec infrastructure network services
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.