CVE-2022-32212

A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*

Information

Published : 2022-07-14 15:15

Updated : 2022-07-21 14:52


NVD link : CVE-2022-32212

Mitre link : CVE-2022-32212


JSON object : View

Products Affected

nodejs

  • node.js
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')