OSV 1.4.0 · github-reviewed · 修改于 2023-10-09 08:42
发布时间
2022-05-13 09:08
GitHub 审查时间
2023-07-21 06:39
NVD 发布时间
2018-05-17 22:29
源文件
advisories/github-reviewed/2022/05/GHSA-wq4c-wm6x-jw44/GHSA-wq4c-wm6x-jw44.json
该公告已于 2023-10-09 08:42 撤回
内容仅用于保留外部引用,请不要将其当作仍然有效的安全结论。
This advisory has been withdrawn because this vulnerability affects inspector code in https://github.com/nodejs/node, not the legacy debugger at https://github.com/node-inspector/node-inspector. https://github.com/nodejs/node is not in a supported ecosystem.
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious websites open in a web browser on the same computer, or another computer with network access to the computer running the Node.js process. A malicious website could use a DNS rebinding attack to trick the web browser to bypass same-origin-policy checks and to allow HTTP connections to localhost or to hosts on the local network. If a Node.js process with the debug port active is running on localhost or on a host on the local network, the malicious website could connect to it as a debugger, and get full code execution access.