« Volver al listado

CVE-2022-2421

Estado: AnalizadaCrítica (9.8)—

Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2421",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-2421",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-20T14:40:01.867350Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "csirt@divd.nl",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "csirt@divd.nl",
      "affectedData": [
        {
          "vendor": "Socket.io",
          "product": "Socket.io-Parser",
          "versions": [
            {
              "status": "affected",
              "version": "4.x",
              "lessThan": "4.2.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-10-26T10:15:16.780",
  "references": [
    {
      "url": "https://csirt.divd.nl/CVE-2022-2421",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "csirt@divd.nl"
    },
    {
      "url": "https://csirt.divd.nl/DIVD-2022-00045",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "csirt@divd.nl"
    },
    {
      "url": "https://csirt.divd.nl/CVE-2022-2421",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://csirt.divd.nl/DIVD-2022-00045",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "csirt@divd.nl",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object."
    },
    {
      "lang": "es",
      "value": "Debido a una incorrecta comprobación de tipos en el análisis de archivos adjuntos de la biblioteca js Socket.io, es posible sobrescribir el objeto _placeholder, lo que permite a un atacante colocar referencias a funciones en lugares arbitrarios en el objeto de consulta resultante"
    }
  ],
  "lastModified": "2026-06-17T04:41:51.947",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A71164DE-F49F-4BB6-8F5B-B3F1CAF74021",
              "versionEndExcluding": "3.3.3"
            },
            {
              "criteria": "cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "341DC336-DDBF-4EB8-BD8C-39427AABD9E6",
              "versionEndExcluding": "3.4.2",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09139258-15B4-4ABF-B211-21A4BD80B123",
              "versionEndExcluding": "4.0.5",
              "versionStartIncluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:socket:socket.io-parser:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9EC7F6F-846D-4F2B-B808-8C90894EC0C0",
              "versionEndExcluding": "4.2.1",
              "versionStartIncluding": "4.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "csirt@divd.nl"
}