CVE-2021-22930 is a critical use-after-free vulnerability affecting Node.js versions prior to 16.6.0, 14.17.4, and 12.22.4, as well as products from Debian, NetApp, and Siemens. With a CVSS score of 9.8, it allows unauthenticated remote attackers to exploit memory corruption, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0, < 12.22.4CPE match | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.17.4CPE match | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.6.0CPE match | cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:* | ||
>= 12.0.0, < 12.22.4CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* | ||
>= 14.0.0, < 14.17.4CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-22930
Dec 14, 2021Node.js before 16.6.0 14.17.4 and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption to change process behavior.
Oct 12, 2021nodejs: Use-after-free on close http2 on stream canceling
Jul 29, 2021