---
title: "CVE-2022-43548\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-43548?format=md
keywords: index, follow
---

# CVE-2022-43548

Publication date 5 December 2022

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.1 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-43548?format=md#impact-score)

Toggle side navigation

## Description

A OS Command Injection vulnerability exists in Node.js versions <14.21.1,
<16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that
can easily be bypassed because IsIPAddress does not properly check if an IP
address is invalid before making DBS requests allowing rebinding
attacks.The fix for this issue in
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was
incomplete and this new CVE is to complete the fix.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| nodejs | 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Fixed 12.22.9~dfsg-1ubuntu3.2 |
| 20.04 LTS focal | Fixed 10.19.0~dfsg-3ubuntu1.3 |
| 18.04 LTS bionic | Fixed 8.10.0~dfsg-2ubuntu0.4+esm4  Ubuntu Pro |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.1 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.1 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-43548)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-43548)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-43548)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-43548)

### Related Ubuntu Security Notices (USN)

+ [USN-6491-1](https://usn.ubuntu.com/USN-6491-1)
+ Node.js vulnerabilities
+ 21 November 2023

### Other references

* <https://nodejs.org/en/blog/vulnerability/november-2022-security-releases/#dns-rebinding-in-inspect-via-invalid-octal-ip-address-medium-cve-2022-43548>
* <https://www.cve.org/CVERecord?id=CVE-2022-43548>
