HIGH · 7.5

CVE-2021-22884

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordin...

Vulnerability Description

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NodejsNode.Js>= 10.0.0, < 10.24.0
FedoraprojectFedora32
NetappActive Iq Unified Manager-
NetappE-Series Performance Analyzer-
NetappOncommand Insight-
NetappOncommand Workflow Automation-
NetappSnapcenter-
OracleGraalvm19.3.5
OracleJd Edwards Enterpriseone Tools< 9.2.6.0
OracleMysql Cluster<= 8.0.25
OracleNosql Database< 20.3
OraclePeoplesoft Enterprise Peopletools8.58
SiemensSinec Infrastructure Network Services< 1.0.1.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22884?

CVE-2021-22884 is a vulnerability with a CVSS score of 7.5 (HIGH). Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordin...

How severe is CVE-2021-22884?

CVE-2021-22884 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-22884?

Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js, Fedoraproject Fedora, Netapp Active Iq Unified Manager, Netapp E-Series Performance Analyzer, Netapp Oncommand Insight.