发布时间: 2023年9月2日
修改时间: 2024年10月31日
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
NVD | openEuler | |
---|---|---|
Confidentiality | High | High |
Attack Vector | Network | Network |
CVSS评分 | 8.1 | 8.1 |
Attack Complexity | High | High |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | High | High |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1647 | nodejs security update | 2023年9月2日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | nodejs | Fixed |
KY3.4-5A | nodejs | Fixed |
KY3.5.1 | nodejs | Fixed |
KY3.5.2 | nodejs | Fixed |