CVE-2021-3672

CVSS v3.1 5.6 (Medium)
56% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.18 % (56th)
0.18% Progress
Affected Products 17
Advisories 44

A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2021-11-23 19:15:07
(2 years ago)
Updated Date
2024-01-05 10:15:10
(8 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  C-ares Project C-ares from 1.0.0 version and prior 1.17.2 version cpe:2.3:a:c-ares_project:c-ares >= 1.0.0 < 1.17.2

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 33 cpe:2.3:o:fedoraproject:fedora:33
  Fedoraproject Fedora 34 cpe:2.3:o:fedoraproject:fedora:34

Configuration #3

    CPE23 From Up To
  Redhat Enterprise Linux 7.0 cpe:2.3:o:redhat:enterprise_linux:7.0
  Redhat Enterprise Linux 7.7 cpe:2.3:o:redhat:enterprise_linux:7.7
  Redhat Enterprise Linux 8.0 cpe:2.3:o:redhat:enterprise_linux:8.0
  Redhat Enterprise Linux Computer Node 1 cpe:2.3:o:redhat:enterprise_linux_computer_node:1
  Redhat Enterprise Linux Eus 7.7 cpe:2.3:o:redhat:enterprise_linux_eus:7.7
  Redhat Enterprise Linux Eus 8.1 cpe:2.3:o:redhat:enterprise_linux_eus:8.1
  Redhat Enterprise Linux Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_eus:8.2
  Redhat Enterprise Linux Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_eus:8.4
  Redhat Enterprise Linux for Ibm Z Systems 8.0 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.1 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.1
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.2
  Redhat Enterprise Linux for Ibm Z Systems Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:8.4
  Redhat Enterprise Linux for Power Little Endian 8.0 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0
  Redhat Enterprise Linux for Power Little Endian Eus 8.1 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.1
  Redhat Enterprise Linux for Power Little Endian Eus 8.2 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.2
  Redhat Enterprise Linux for Power Little Endian Eus 8.4 cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:8.4
  Redhat Enterprise Linux Server Aus 8.2 cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2
  Redhat Enterprise Linux Server Aus 8.4 cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4
  Redhat Enterprise Linux Server Tus 8.2 cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2
  Redhat Enterprise Linux Server Tus 8.4 cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4
  Redhat Enterprise Linux Server Update Services for Sap Solutions 8.1 cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.1
  Redhat Enterprise Linux Server Update Services for Sap Solutions 8.2 cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.2
  Redhat Enterprise Linux Server Update Services for Sap Solutions 8.4 cpe:2.3:o:redhat:enterprise_linux_server_update_services_for_sap_solutions:8.4
  Redhat Enterprise Linux Tus 8.4 cpe:2.3:o:redhat:enterprise_linux_tus:8.4
  Redhat Enterprise Linux Workstation 1 cpe:2.3:o:redhat:enterprise_linux_workstation:1

Configuration #4

    CPE23 From Up To
  Siemens Sinec Infrastructure Network Services prior 1.0.1.1 version cpe:2.3:a:siemens:sinec_infrastructure_network_services < 1.0.1.1

Configuration #5

    CPE23 From Up To
  Nodejs Node.js from 12.0.0 version and 12.12.0 and prior versions cpe:2.3:a:nodejs:node.js::*:*:*:- >= 12.0.0 <= 12.12.0
  Nodejs Node.js from 12.13.0 version and prior 12.22.5 version cpe:2.3:a:nodejs:node.js::*:*:*:lts >= 12.13.0 < 12.22.5
  Nodejs Node.js from 14.0.0 version and 14.14.0 and prior versions cpe:2.3:a:nodejs:node.js::*:*:*:- >= 14.0.0 <= 14.14.0
  Nodejs Node.js from 14.15.0 version and prior 14.17.5 version cpe:2.3:a:nodejs:node.js::*:*:*:lts >= 14.15.0 < 14.17.5
  Nodejs Node.js from 16.0.0 version and prior 16.6.2 version cpe:2.3:a:nodejs:node.js::*:*:*:- >= 16.0.0 < 16.6.2

Configuration #6

    CPE23 From Up To
  Pgbouncer 1.17.0 and prior versions cpe:2.3:a:pgbouncer:pgbouncer <= 1.17.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...