nodejs: DNS rebinding in inspect via invalid octal IP address
Published Dec 5, 2022
8.1
HIGHCVSS 3.1
EPSS 14.55%
Description
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.*
- Version 11.0StatusaffectedConstraints<11.*
- Version 12.0StatusaffectedConstraints<12.*
- Version 13.0StatusaffectedConstraints<13.*
- Version 14.0StatusaffectedConstraints<14.21.1
- Version 15.0StatusaffectedConstraints<15.*
- Version 16.0StatusaffectedConstraints<16.18.1
- Version 17.0StatusaffectedConstraints<17.*
- Version 18.0StatusaffectedConstraints<18.12.1
- Version 19.0StatusaffectedConstraints<19.0.1
- Version 4.0StatusaffectedConstraints<4.*
- Version 5.0StatusaffectedConstraints<5.*
- Version 6.0StatusaffectedConstraints<6.*
- Version 7.0StatusaffectedConstraints<7.*
- Version 8.0StatusaffectedConstraints<8.*
- Version 9.0StatusaffectedConstraints<9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Node.js | Node | unaffected |
|
Configuration 1
- ≥ 14.0.0 · ≤ 14.14.0
- ≥ 14.15.0 · < 14.21.1
- ≥ 16.0.0 · ≤ 16.12.0
- ≥ 16.13.0 · < 16.18.1
- ≥ 18.0.0 · ≤ 18.11.0
- 18.12.0
- 19.0.0
Configuration 2
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 8
nodejs:14-8070020221212161539.bd1311ed
Fixed · RHSA-2023:0050
Red Hat Enterprise Linux 8
nodejs:16-8070020221207164159.bd1311ed
Fixed · RHSA-2022:9073
Red Hat Enterprise Linux 8
nodejs:18-8070020221118123310.bd1311ed
Fixed · RHSA-2022:8833
Red Hat Enterprise Linux 8.4 Extended Update Support
nodejs:14-8040020230306170312.522a0ee4
Fixed · RHSA-2023:1533
Red Hat Enterprise Linux 8.6 Extended Update Support
nodejs:14-8060020230306170237.ad008a3a
Fixed · RHSA-2023:1742
Red Hat Enterprise Linux 9
nodejs-1:16.18.1-3.el9_1
Fixed · RHSA-2023:0321
Red Hat Enterprise Linux 9
nodejs:18-9010020221118120946.rhel9
Fixed · RHSA-2022:8832
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-0:14.21.1-3.el7
Fixed · RHSA-2023:0612
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs14-nodejs-nodemon-0:2.0.20-2.el7
Fixed · RHSA-2023:0612
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:14-8070020221212161539.bd1311ed | Fixed | RHSA-2023:0050 |
| Red Hat Enterprise Linux 8 | nodejs:16-8070020221207164159.bd1311ed | Fixed | RHSA-2022:9073 |
| Red Hat Enterprise Linux 8 | nodejs:18-8070020221118123310.bd1311ed | Fixed | RHSA-2022:8833 |
| Red Hat Enterprise Linux 8.4 Extended Update Support | nodejs:14-8040020230306170312.522a0ee4 | Fixed | RHSA-2023:1533 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | nodejs:14-8060020230306170237.ad008a3a | Fixed | RHSA-2023:1742 |
| Red Hat Enterprise Linux 9 | nodejs-1:16.18.1-3.el9_1 | Fixed | RHSA-2023:0321 |
| Red Hat Enterprise Linux 9 | nodejs:18-9010020221118120946.rhel9 | Fixed | RHSA-2022:8832 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-0:14.21.1-3.el7 | Fixed | RHSA-2023:0612 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs14-nodejs-nodemon-0:2.0.20-2.el7 | Fixed | RHSA-2023:0612 |
No package ranges for this CVE.
Remediation
Red Hat statement
Redhat has marked this vulnerability as moderate for two primary reasons. 1. The vulnerable inspect functionality might not be enabled, exposed, or reachable in many deployments. 2.The code path might require very specific configurations or conditions (e.g. DNS rebinding, certain host/IP setups) that are rare in default environments.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-43548 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2140911 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-46545 Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00038.html mailing-listMailing ListThird Party Advisory
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/ PatchVendor Advisory
- https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/#dns-rebinding-in-inspect-via-invalid-octal-ip-address-medium-cve-2022-43548
- https://nvd.nist.gov/vuln/detail/CVE-2022-43548
- https://security.netapp.com/advisory/ntap-20230120-0004/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230427-0007/
- https://www.cve.org/CVERecord?id=CVE-2022-43548
- https://www.debian.org/security/2023/dsa-5326 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-43548 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2140911 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-46545 | Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/02/msg00038.html | mailing-listMailing ListThird Party Advisory | |
| https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/ | PatchVendor Advisory | |
| https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/#dns-rebinding-in-inspect-via-invalid-octal-ip-address-medium-cve-2022-43548 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-43548 | ||
| https://security.netapp.com/advisory/ntap-20230120-0004/ | Third Party Advisory | |
| https://security.netapp.com/advisory/ntap-20230427-0007/ | ||
| https://www.cve.org/CVERecord?id=CVE-2022-43548 | ||
| https://www.debian.org/security/2023/dsa-5326 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.