Bug 1182620 (CVE-2021-22884)

Summary: VUL-0: CVE-2021-22884: nodejs10,nodejs12,nodejs14,nodejs: DNS rebinding in --inspect
Product: [Novell Products] SUSE Security Incidents Reporter: Gianluca Gabrielli <gianluca.gabrielli>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: stoyan.manolov
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: CVSSv3.1:SUSE:CVE-2021-22884:5.8:(AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L)
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Gianluca Gabrielli 2021-02-23 15:12:43 UTC
CVE-2021-22884

Affected Node.js versions are vulnerable to denial of service attacks when the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

Impacts:

    All versions of the 15.x, 14.x, 12.x and 10.x releases lines
Comment 1 Gianluca Gabrielli 2021-02-23 15:17:24 UTC
Upstream patches:

nodejs10: d1cf6a9b0f [0]
nodejs12: 1564752d55 [1]
nodejs14: 1ca3f5abcb [2]
nodejs  : 43ae9c46c3 [3]

--
[0] https://github.com/nodejs/node/commit/d1cf6a9b0f
[1] https://github.com/nodejs/node/commit/1564752d55
[2] https://github.com/nodejs/node/commit/1ca3f5abcb
[3] https://github.com/nodejs/node/commit/43ae9c46c3
Comment 2 Adam Majer 2021-02-23 15:26:12 UTC
nodejs8 is also affected. Same patch as others.
Comment 3 OBSbugzilla Bot 2021-02-23 19:00:17 UTC
This is an autogenerated message for OBS integration:
This bug (1182620) was mentioned in
https://build.opensuse.org/request/show/874671 Factory / nodejs10
https://build.opensuse.org/request/show/874672 Factory / nodejs15
Comment 5 Adam Majer 2021-02-24 09:36:03 UTC
Fixes for all codestreams submitted. Reassigning to security-team for tracking purposes.
Comment 6 Swamp Workflow Management 2021-02-26 20:18:10 UTC
SUSE-SU-2021:0650-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 12 (src):    nodejs14-14.16.0-6.9.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2021-02-26 20:21:44 UTC
SUSE-SU-2021:0651-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    nodejs12-12.21.0-4.13.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2021-02-26 20:26:17 UTC
SUSE-SU-2021:0648-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    nodejs14-14.16.0-5.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-02-26 20:27:34 UTC
SUSE-SU-2021:0649-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 12 (src):    nodejs12-12.21.0-1.29.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2021-02-28 02:17:50 UTC
openSUSE-SU-2021:0357-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nodejs12-12.21.0-lp152.3.12.1
Comment 11 Swamp Workflow Management 2021-02-28 02:18:52 UTC
openSUSE-SU-2021:0356-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nodejs14-14.16.0-lp152.8.1
Comment 12 Swamp Workflow Management 2021-03-02 14:19:58 UTC
SUSE-SU-2021:0673-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 12 (src):    nodejs10-10.24.0-1.36.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2021-03-02 14:21:27 UTC
SUSE-SU-2021:0674-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
SUSE Manager Server 4.0 (src):    nodejs10-10.24.0-1.33.2
SUSE Manager Retail Branch Server 4.0 (src):    nodejs10-10.24.0-1.33.2
SUSE Manager Proxy 4.0 (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Server for SAP 15 (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Server 15-SP1-BCL (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Server 15-LTSS (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    nodejs10-10.24.0-1.33.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    nodejs10-10.24.0-1.33.2
SUSE Enterprise Storage 6 (src):    nodejs10-10.24.0-1.33.2
SUSE CaaS Platform 4.0 (src):    nodejs10-10.24.0-1.33.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 14 Swamp Workflow Management 2021-03-02 23:18:30 UTC
SUSE-SU-2021:0686-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1182620
CVE References: CVE-2021-22884
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    nodejs8-8.17.0-10.9.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 15 Swamp Workflow Management 2021-03-03 05:18:08 UTC
openSUSE-SU-2021:0372-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1182333,1182619,1182620
CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nodejs10-10.24.0-lp152.2.12.1
Comment 16 Swamp Workflow Management 2021-03-06 08:17:42 UTC
openSUSE-SU-2021:0389-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1182620
CVE References: CVE-2021-22884
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nodejs8-8.17.0-lp152.3.11.1
Comment 20 Swamp Workflow Management 2021-08-05 14:47:32 UTC
SUSE-SU-2021:2620-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1182620,1184450,1187976,1187977
CVE References: CVE-2020-7774,CVE-2021-22884,CVE-2021-23362,CVE-2021-27290
JIRA References: 
Sources used:
SUSE Manager Server 4.0 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Manager Retail Branch Server 4.0 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Manager Proxy 4.0 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Server for SAP 15 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Server 15-SP1-BCL (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Server 15-LTSS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src):    nodejs-common-2.0-3.2.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE Enterprise Storage 6 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2
SUSE CaaS Platform 4.0 (src):    nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.