Wind River Support Network

HomeDefectsLIN1022-2340
Fixed

LIN1022-2340 : Security Advisory - nodejs - CVE-2022-43548

Created: Nov 6, 2022    Updated: Jan 15, 2023
Resolved Date: Jan 3, 2023
Found In Version: 10.22.33.1
Fix Version: 10.22.33.4
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.

https://nvd.nist.gov/vuln/detail/CVE-2022-43548

CVEs


Live chat
Online