Multiple vulnerabilities in Red Hat Application Interconnect



Risk High
Patch available YES
Number of vulnerabilities 13
CVE-ID CVE-2022-2879
CVE-2022-2880
CVE-2022-28327
CVE-2022-41715
CVE-2022-41723
CVE-2022-41724
CVE-2022-41725
CVE-2023-24534
CVE-2023-24536
CVE-2023-24537
CVE-2023-24538
CVE-2023-24539
CVE-2023-29400
CWE-ID CWE-399
CWE-20
CWE-190
CWE-400
CWE-835
CWE-94
CWE-79
Exploitation vector Network
Public exploit N/A
Vulnerable software
Red Hat Application Interconnect
Server applications / Other server solutions

skupper-router (Red Hat package)
Operating systems & Components / Operating system package or component

skupper-cli (Red Hat package)
Operating systems & Components / Operating system package or component

qpid-proton (Red Hat package)
Operating systems & Components / Operating system package or component

libwebsockets (Red Hat package)
Operating systems & Components / Operating system package or component

jsoncpp (Red Hat package)
Operating systems & Components / Operating system package or component

Vendor Red Hat Inc.

Security Bulletin

This security bulletin contains information about 13 vulnerabilities.

1) Resource management error

EUVDB-ID: #VU68387

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-2879

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to absent limits on the maximum size of file headers within the Reader.Read method in archive/tar. A remote attacker can pass a specially crafted file to the application and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Input validation error

EUVDB-ID: #VU68389

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-2880

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform parameter smuggling attacks.

The vulnerability exists due to incorrect handling of requests forwarded by ReverseProxy in net/http/httputil. A remote attacker can supply specially crafted parameters that cannot be parsed and are rejected by net/http and force the application to include these parameters into the forwarding request. As a result, a remote attacker can smuggle potentially dangerous HTTP parameters into the request.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Integer overflow

EUVDB-ID: #VU64269

Risk: Low

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-28327

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to integer overflow in the Golang's library crypto/elliptic. A remote attacker can send a specially crafted scalar input longer than 32 bytes to cause P256().ScalarMult or P256().ScalarBaseMult to panic and perform a denial of service attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Resource exhaustion

EUVDB-ID: #VU68390

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-41715

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in regexp/syntax when handling regular expressions. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Resource exhaustion

EUVDB-ID: #VU72686

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-41723

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources in the HPACK decoder. A remote attacker can send a specially crafted HTTP/2 stream to the application, cause resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Resource management error

EUVDB-ID: #VU72685

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-41724

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources in crypto/tls when handling large TLS handshake records. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.

The vulnerability affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Resource exhaustion

EUVDB-ID: #VU73722

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2022-41725

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper control over internal resources in net/http and mime/multipart. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Resource exhaustion

EUVDB-ID: #VU74571

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-24534

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when parsing HTTP and MIME headers in net/textproto. A remote attacker can cause an HTTP server to allocate large amounts of memory from a small request and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Resource management error

EUVDB-ID: #VU74572

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-24536

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within mime/multipart and net/textproto components when parsing multipart forms. A remote attacker can pass specially crafted request to the application and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Infinite loop

EUVDB-ID: #VU74573

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-24537

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when calling any of the Parse functions on Go source code which contains //line directives with very large line numbers. A remote attacker can consume all available system resources and cause denial of service conditions.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Code Injection

EUVDB-ID: #VU74574

Risk: High

CVSSv4.0: 8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2023-24538

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation in html/template when handling JavaScript templates that contain backticks in code. If a template contains a Go template action within a JavaScript template literal, the contents of the action can be used to terminate the literal, injecting arbitrary JavaScript code into the Go template.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Cross-site scripting

EUVDB-ID: #VU75790

Risk: Medium

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-24539

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when handling angle brackets in CSS context. A remote attacker can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Cross-site scripting

EUVDB-ID: #VU75792

Risk: Medium

CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-29400

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data when processing HTML attributes. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Red Hat Application Interconnect: before 1.4

skupper-router (Red Hat package): before 2.4.1-2.el8

skupper-cli (Red Hat package): before 1.4.1-2.el8

qpid-proton (Red Hat package): before 0.37.0-2.el8ai

libwebsockets (Red Hat package): before 4.3.1-1.el8ai

jsoncpp (Red Hat package): before 1.9.4-3.el9

CPE2.3 External links

https://access.redhat.com/errata/RHSA-2023:4003


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###