SB2021022617 - DNS rebinding in nodejs (Alpine package)



SB2021022617 - DNS rebinding in nodejs (Alpine package)

Published: February 26, 2021

Security Bulletin ID SB2021022617
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) DNS rebinding (CVE-ID: CVE-2021-22884)

The vulnerability allows a remote attacker to perform DNS rebinding attack.

The vulnerability exists due to the application whitelist includes the “localhost6” name. When “localhost6” is not present in /etc/hosts, it is treated an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain.


Remediation

Install update from vendor's website.