peter bassill · operator
$ cve CVE-2021-22931 JSON

CVE-2021-22931

9.8
CRITICAL · CVSS 3.1 · EPSS 22% (pctl 98)

Patch early

EPSS 22% — above the 10% action threshold.

Description

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS21.95% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-170
On CISA KEVno
Public exploitnone known
Published2021-08-16
Last modified2026-06-17

Affected (10)

VendorProduct
netappactive iq unified manager
netappnextgen api
netapponcommand insight
netapponcommand workflow automation
netappsnapcenter
nodejsnode.js
oraclegraalvm
oraclemysql cluster
oraclepeoplesoft enterprise peopletools
siemenssinec infrastructure network services

References

→ the Explorer  ·  watch your stack  ·  NVD