9.8

CVE-2021-22931

Exploit

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

Data is provided by the National Vulnerability Database (NVD)
NodejsNode.Js SwEdition- Version >= 12.0.0 <= 12.12.0
NodejsNode.Js SwEditionlts Version >= 12.13.0 < 12.22.5
NodejsNode.Js SwEdition- Version >= 14.0.0 <= 14.14.0
NodejsNode.Js SwEditionlts Version >= 14.15.0 < 14.17.5
NodejsNode.Js SwEdition- Version >= 16.0.0 < 16.6.2
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappNextgen Api Version-
NetappOncommand Insight Version-
NetappSnapcenter Version-
OracleGraalvm Version20.3.3 SwEditionenterprise
OracleGraalvm Version21.2.0 SwEditionenterprise
OracleMysql Cluster Version <= 8.0.26
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.74% 0.72
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-170 Improper Null Termination

The product does not terminate or incorrectly terminates a string or array with a null character or equivalent terminator.

CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.