CVE-2021-22931
Summary
| CVE | CVE-2021-22931 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-16 19:15:00 UTC |
| Updated | 2024-01-05 10:15:00 UTC |
| Description | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159398 Oracle Enterprise Linux Security Update for nodejs:12 (ELSA-2021-3623)
- 159408 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2021-3666)
- 239590 Red Hat Update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon (RHSA-2021:3281)
- 239591 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2021:3280)
- 239645 Red Hat Update for nodejs:12 (RHSA-2021:3623)
- 239654 Red Hat Update for nodejs:12 (RHSA-2021:3639)
- 239655 Red Hat Update for nodejs:12 (RHSA-2021:3638)
- 239658 Red Hat Update for nodejs:14 (RHSA-2021:3666)
- 375786 Node.js Remote Code Execution Vulnerability Aug 2021
- 375877 Kibana Multiple Security Vulnerabilities (ESA-2021-21, ESA-2021-22, ESA-2021-24)
- 376035 F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Node.js Vulnerabilities (K53225395)
- 376257 Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2022)
- 377157 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2021:0072)
- 500444 Alpine Linux Security Update for nodejs
- 501453 Alpine Linux Security Update for nodejs
- 501884 Alpine Linux Security Update for nodejs-current
- 502123 Alpine Linux Security Update for nodejs-current
- 504207 Alpine Linux Security Update for nodejs
- 505102 Alpine Linux Security Update for nodejs-current
- 690032 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (b092bd4f-1b16-11ec-9d9d-0022489ad614)
- 690192 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (c9387e4d-2f5f-11ec-8be6-d4c9ef517024)
- 710820 Gentoo Linux c-ares Multiple Vulnerabilities (GLSA 202401-02)
- 751061 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:2875-1)
- 751071 OpenSUSE Security Update for nodejs12 (openSUSE-SU-2021:1214-1)
- 751093 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:2953-1)
- 751112 OpenSUSE Security Update for nodejs10 (openSUSE-SU-2021:1239-1)
- 751171 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:3211-1)
- 751178 OpenSUSE Security Update for nodejs14 (openSUSE-SU-2021:1313-1)
- 900315 CBL-Mariner Linux Security Update for nodejs 14.17.2
- 901815 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (6743-1)
- 902921 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (5422)
- 904931 Common Base Linux Mariner (CBL-Mariner) Security Update for grpc (12345)
- 904956 Common Base Linux Mariner (CBL-Mariner) Security Update for python-gevent (12410)
- 905113 Common Base Linux Mariner (CBL-Mariner) Security Update for python-gevent (12610)
- 905164 Common Base Linux Mariner (CBL-Mariner) Security Update for grpc (12493)
- 908032 Common Base Linux Mariner (CBL-Mariner) Security Update for python-gevent (32282-1)
- 940217 AlmaLinux Security Update for nodejs:12 (ALSA-2021:3623)
- 940388 AlmaLinux Security Update for nodejs:14 (ALSA-2021:3666)
- 960018 Rocky Linux Security Update for nodejs:12 (RLSA-2021:3623)
- 960050 Rocky Linux Security Update for nodejs:14 (RLSA-2021:3666)