CVE-2022-32212
Summary
| CVE | CVE-2022-32212 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-14 15:15:00 UTC |
| Updated | 2023-02-23 20:15:00 UTC |
| Description | A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160092 Oracle Enterprise Linux Security Update for nodejs:14 (ELSA-2022-6448)
- 160094 Oracle Enterprise Linux Security Update for nodejs:16 (ELSA-2022-6449)
- 160111 Oracle Enterprise Linux Security Update for nodejs and nodejs-nodemon (ELSA-2022-6595)
- 181111 Debian Security Update for nodejs (DLA 3137-1)
- 181502 Debian Security Update for nodejs (DSA 5326-1)
- 184296 Debian Security Update for nodejs (CVE-2022-32212)
- 199926 Ubuntu Security Notification for Node.js Vulnerabilities (USN-6491-1)
- 240655 Red Hat Update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon (RHSA-2022:6389)
- 240656 Red Hat Update for nodejs:14 (RHSA-2022:6448)
- 240660 Red Hat Update for nodejs:16 (RHSA-2022:6449)
- 240676 Red Hat Update for nodejs and nodejs-nodemon (RHSA-2022:6595)
- 240736 Red Hat Update for nodejs:14 (RHSA-2022:6985)
- 283356 Fedora Security Update for nodejs (FEDORA-2022-de515f765f)
- 283357 Fedora Security Update for nodejs (FEDORA-2022-52dec6351a)
- 283432 Fedora Security Update for nodejs (FEDORA-2022-1667f7b60a)
- 296083 Oracle Solaris 11.4 Support Repository Update (SRU) 49.126.2 Missing (CPUOCT2022)
- 296098 Oracle Solaris 11.4 Support Repository Update (SRU) 52.132.2 Missing (CPUOCT2022)
- 355273 Amazon Linux Security Advisory for nodejs : ALAS2023-2023-084
- 376730 Node.js Multiple Vulnerabilities (JULY 2022)
- 377624 Alibaba Cloud Linux Security Update for nodejs:14 (ALINUX3-SA-2022:0165)
- 378004 Splunk Enterprise Multiple Vulnerabilities (SVD-2023-0215,SVD-2023-0211,SVD-2023-0208)
- 502445 Alpine Linux Security Update for nodejs
- 502446 Alpine Linux Security Update for nodejs
- 502447 Alpine Linux Security Update for nodejs-current
- 502513 Alpine Linux Security Update for nodejs-current
- 690894 Free Berkeley Software Distribution (FreeBSD) Security Update for node.js (b9210706-feb0-11ec-81fa-1c697a616631)
- 752362 SUSE Enterprise Linux Security Update for nodejs14 (SUSE-SU-2022:2425-1)
- 752367 SUSE Enterprise Linux Security Update for nodejs12 (SUSE-SU-2022:2430-1)
- 752490 SUSE Enterprise Linux Security Update for nodejs10 (SUSE-SU-2022:2855-1)
- 753157 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2022:2491-1)
- 753475 SUSE Enterprise Linux Security Update for nodejs16 (SUSE-SU-2022:2551-1)
- 753698 SUSE Enterprise Linux Security Update for nodejs18 (SUSE-SU-2023:0419-1)
- 902528 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (10152)
- 902535 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (10149)
- 902706 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (10152-1)
- 903824 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (10149-1)
- 940654 AlmaLinux Security Update for nodejs:14 (ALSA-2022:6448)
- 940678 AlmaLinux Security Update for nodejs and nodejs-nodemon (ALSA-2022:6595)
- 960189 Rocky Linux Security Update for nodejs:14 (RLSA-2022:6448)
- 960277 Rocky Linux Security Update for nodejs:16 (RLSA-2022:6449)
- 960531 Rocky Linux Security Update for nodejs and nodejs-nodemon (RLSA-2022:6595)