A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3344-1 | nodejs security update | 
  Debian DSA | 
                DSA-5326-1 | nodejs security update | 
  EUVD | 
                EUVD-2022-46545 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix. | 
  Ubuntu USN | 
                USN-6491-1 | Node.js vulnerabilities | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Thu, 24 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-04-30T05:55:04.408Z
Reserved: 2022-10-20T00:00:00.000Z
Link: CVE-2022-43548
Updated: 2024-08-03T13:32:59.546Z
Status : Modified
Published: 2022-12-05T22:15:10.923
Modified: 2025-04-24T14:15:38.157
Link: CVE-2022-43548
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 Debian DSA
 EUVD
 Ubuntu USN