Aller au contenu principal
HIGH

CVE-2021-22884

CVSS v3

7.5

HIGH

Score EPSS

32.4 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

Détails techniques

Publiée le
2021-03-03

Questions fréquentes

Qu’est-ce que CVE-2021-22884 ?

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

CVE-2021-22884 est-elle activement exploitée ?

Aucune exploitation active de CVE-2021-22884 n’est confirmée. Son score EPSS était de 32.4 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2021-22884 ?

CVE-2021-22884 a un score de base CVSS v3 de 7.5 (gravité HIGH).

CVE-2021-22884 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite