Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster DLA-3137-1 Critical Node.js Command Injection Threat

debian lts
Calendar Grey October 5, 2022
Dist Debian Esm H88
Numerous vulnerabilities in Node.js tackled by Debian LTS DLA-3140-1 prompting users to update packages.
Multiple vulnerabilities were discovered in Node.js, a JavaScript runtime environment, which could result in memory corruption, invalid certificate validation, prototype pollution ...

Summary

CVE-2021-22930, CVE-2021-22940

Use after free attack where an attacker might be able to exploit
the memory corruption, to change process behavior.

CVE-2021-22939

If the Node.js https API was used incorrectly and "undefined" was
in passed for the "rejectUnauthorized" parameter, no error was
returned and connections to servers with an expired certificate
would have been accepted.

CVE-2022-21824

Due to the formatting logic of the "console.table()" function it
was not safe to allow user controlled input to be passed to the
"properties" parameter while simultaneously passing a plain object
with at least one property as the first parameter, which could be
"__proto__".

CVE-2022-32212

OS Command Injection vulnerability due to an insufficient
IsAllowedHost check that can easily be bypassed because
IsIPAddress does not properly check if an IP address is invalid
before making DBS requests allowing rebinding attacks.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: nodejs
Version: 10.24.0~dfsg-1~deb10u2
CVE ID: CVE-2021-22930 CVE-2021-22939 CVE-2021-22940 CVE-2022-21824
Debian Bug: 1004177

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here