Bugzilla – Bug 1182620
VUL-0: CVE-2021-22884: nodejs10,nodejs12,nodejs14,nodejs: DNS rebinding in --inspect
Last modified: 2022-11-30 08:20:56 UTC
CVE-2021-22884 Affected Node.js versions are vulnerable to denial of service attacks when the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160. Impacts: All versions of the 15.x, 14.x, 12.x and 10.x releases lines
Upstream patches: nodejs10: d1cf6a9b0f [0] nodejs12: 1564752d55 [1] nodejs14: 1ca3f5abcb [2] nodejs : 43ae9c46c3 [3] -- [0] https://github.com/nodejs/node/commit/d1cf6a9b0f [1] https://github.com/nodejs/node/commit/1564752d55 [2] https://github.com/nodejs/node/commit/1ca3f5abcb [3] https://github.com/nodejs/node/commit/43ae9c46c3
nodejs8 is also affected. Same patch as others.
This is an autogenerated message for OBS integration: This bug (1182620) was mentioned in https://build.opensuse.org/request/show/874671 Factory / nodejs10 https://build.opensuse.org/request/show/874672 Factory / nodejs15
Fixes for all codestreams submitted. Reassigning to security-team for tracking purposes.
SUSE-SU-2021:0650-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 12 (src): nodejs14-14.16.0-6.9.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:0651-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): nodejs12-12.21.0-4.13.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:0648-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): nodejs14-14.16.0-5.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:0649-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 12 (src): nodejs12-12.21.0-1.29.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:0357-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: openSUSE Leap 15.2 (src): nodejs12-12.21.0-lp152.3.12.1
openSUSE-SU-2021:0356-1: An update that fixes two vulnerabilities is now available. Category: security (important) Bug References: 1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884 JIRA References: Sources used: openSUSE Leap 15.2 (src): nodejs14-14.16.0-lp152.8.1
SUSE-SU-2021:0673-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 12 (src): nodejs10-10.24.0-1.36.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:0674-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: SUSE Manager Server 4.0 (src): nodejs10-10.24.0-1.33.2 SUSE Manager Retail Branch Server 4.0 (src): nodejs10-10.24.0-1.33.2 SUSE Manager Proxy 4.0 (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Server for SAP 15-SP1 (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Server for SAP 15 (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Server 15-SP1-LTSS (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Server 15-SP1-BCL (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Server 15-LTSS (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): nodejs10-10.24.0-1.33.2 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): nodejs10-10.24.0-1.33.2 SUSE Enterprise Storage 6 (src): nodejs10-10.24.0-1.33.2 SUSE CaaS Platform 4.0 (src): nodejs10-10.24.0-1.33.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2021:0686-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1182620 CVE References: CVE-2021-22884 JIRA References: Sources used: SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): nodejs8-8.17.0-10.9.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2021:0372-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1182333,1182619,1182620 CVE References: CVE-2021-22883,CVE-2021-22884,CVE-2021-23840 JIRA References: Sources used: openSUSE Leap 15.2 (src): nodejs10-10.24.0-lp152.2.12.1
openSUSE-SU-2021:0389-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1182620 CVE References: CVE-2021-22884 JIRA References: Sources used: openSUSE Leap 15.2 (src): nodejs8-8.17.0-lp152.3.11.1
SUSE-SU-2021:2620-1: An update that fixes four vulnerabilities is now available. Category: security (important) Bug References: 1182620,1184450,1187976,1187977 CVE References: CVE-2020-7774,CVE-2021-22884,CVE-2021-23362,CVE-2021-27290 JIRA References: Sources used: SUSE Manager Server 4.0 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Manager Retail Branch Server 4.0 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Manager Proxy 4.0 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Server for SAP 15-SP1 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Server for SAP 15 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Server 15-SP1-LTSS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Server 15-SP1-BCL (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Server 15-LTSS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise Module for Web Scripting 15-SP2 (src): nodejs-common-2.0-3.2.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE Enterprise Storage 6 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 SUSE CaaS Platform 4.0 (src): nodejs-common-2.0-3.2.1, nodejs8-8.17.0-3.47.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.