[ALPINE:CVE-2022-43548] nodejs vulnerability
Severity
High
Affected Packages
22
Fixed Packages
22
CVEs
1
[From CVE-2022-43548] A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
- ID
- ALPINE:CVE-2022-43548
- Severity
- high
- Severity from
- CVE-2022-43548
- URL
- https://security.alpinelinux.org/vuln/CVE-2022-43548
- Published
-
2022-12-05T22:15:10
(21 months ago) - Modified
-
2022-12-05T22:15:10
(21 months ago) - Rights
- Alpine Linux Security Team
- Other Advisories
-
- ALSA-2022:8832
- ALSA-2022:8833
- ALSA-2022:9073
- ALSA-2023:0050
- ALSA-2023:0321
- DSA-5326-1
- ELSA-2022-8832
- ELSA-2022-8833
- ELSA-2023-0050
- ELSA-2023-0321
- GLSA-202405-29
- MS:CVE-2022-43548
- RHSA-2022:8832
- RHSA-2022:8833
- RHSA-2022:9073
- RHSA-2023:0050
- RHSA-2023:0321
- RLSA-2022:8833
- RLSA-2022:9073
- RLSA-2023:0050
- RLSA-2023:0321
- SUSE-SU-2022:3967-1
- SUSE-SU-2022:3968-1
- SUSE-SU-2022:3989-1
- SUSE-SU-2022:4003-1
- SUSE-SU-2022:4084-1
- SUSE-SU-2022:4254-1
- SUSE-SU-2022:4255-1
- SUSE-SU-2022:4301-1
- SUSE-SU-2023:0408-1
- SUSE-SU-2023:0419-1
- USN-6491-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | x86_64 | |
Affected | pkg:apk/alpine/nodejs?arch=x86_64&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | x86_64 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | x86 | |
Affected | pkg:apk/alpine/nodejs?arch=x86&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | x86 | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | s390x | |
Affected | pkg:apk/alpine/nodejs?arch=s390x&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | s390x | |
Fixed | pkg:apk/alpine/nodejs?arch=riscv64&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | riscv64 | |
Affected | pkg:apk/alpine/nodejs?arch=riscv64&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | ppc64le | |
Affected | pkg:apk/alpine/nodejs?arch=ppc64le&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | ppc64le | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | armv7 | |
Affected | pkg:apk/alpine/nodejs?arch=armv7&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | armv7 | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | armhf | |
Affected | pkg:apk/alpine/nodejs?arch=armhf&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | armhf | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-edge | alpine | nodejs | = 18.12.1-r0 | alpine-edge | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-edge | alpine | nodejs | < 18.12.1-r0 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.18 | alpine | nodejs | = 18.12.1-r0 | alpine-3.18 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.18 | alpine | nodejs | < 18.12.1-r0 | alpine-3.18 | aarch64 | |
Fixed | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.17 | alpine | nodejs | = 18.12.1-r0 | alpine-3.17 | aarch64 | |
Affected | pkg:apk/alpine/nodejs?arch=aarch64&distro=alpine-3.17 | alpine | nodejs | < 18.12.1-r0 | alpine-3.17 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |