logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2021-22931

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2021-22931

Description:
Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host names returned by Domain Name Servers in Node.js dns library which can lead to output of wrong hostnames (leading to Domain Hijacking) and injection vulnerabilities in applications using the library.
Last updated date:
01/05/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
04/06/2022
Reference url to background

https://hackerone.com/reports/1178337

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy