CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-22931

CVSS 9.8v3.1pub. 2021-08-16upd. 2024-11-21

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netapp Active Iq Unified Manager

    APP
    Netapp
    all versions
  • Netapp Nextgen Api

    APP
    Netapp
    all versions
  • Netapp Oncommand Insight

    APP
    Netapp
    all versions
  • Netapp Oncommand Workflow Automation

    APP
    Netapp
    all versions
  • Netapp Snapcenter

    APP
    Netapp
    all versions
  • Node.js

    APP
    Nodejs
    12.0.0 – 12.12.012.13.0 – 12.22.5 (excl.)14.0.0 – 14.14.014.15.0 – 14.17.5 (excl.)16.0.0 – 16.6.2 (excl.)
  • Oracle Graalvm

    APP
    Oracle
    20.3.321.2.0
  • Oracle MySQL Cluster

    APP
    Oracle
    ≤ 8.0.26
  • Oracle Peoplesoft Enterprise Peopletools

    APP
    Oracle
    8.578.588.59
  • Siemens Sinec Infrastructure Network Services

    APP
    Siemens
    < 1.0.1.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup

CVE-2019-2725CRITICAL9.8⚠ KEVPL ✓same product

RCE w Oracle WebLogic Server — przejęcie serwera bez uwierzytelnienia

CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX