• 公告ID (KylinSec-SA-2021-1733)

摘要:

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

安全等级: Low

公告ID: KylinSec-SA-2021-1733

发布日期: 2021年9月4日

关联CVE: CVE-2021-22931  

  • 详细介绍

1. 漏洞描述

   

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-22931 KY3.4-4A nodejs Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2021-1731 下一篇:KylinSec-SA-2021-1735