CVE-2018-7160

🟡 Monitoruj

Atak DNS rebinding w Node.js umożliwia zdalne wykonanie kodu przez złośliwe strony.

CVSS
8.8
EPSS
9.9%
Exploit
none
Vendor
nodejs
Opis źródłowy (NVD)

The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)9.9%
Opublikowano (NVD)2018-05-17 14:29:00 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:16:47 UTC
Referencje