Improper authentication in linux-pam - CVE-2024-10963

 

Improper authentication in linux-pam - CVE-2024-10963

Published: November 25, 2024


Vulnerability identifier: #VU100912
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-10963
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in pam_access module where certain rules in its configuration file are mistakenly treated as hostnames. A remote attacker can bypass authentication process and gain unauthorized access to the system.


Affected software

linux-pam
Guardium Data Security Center (GDSC)
IBM Cloud Pak for Watson AIOps
Business Automation Insights
Watson Studio on Cloud Pak for Data
IBM QRadar Incident Forensics
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
openEuler
Ubuntu
Fedora
Submariner
IBM Concert Software
IBM Observability with Instana
Multicluster GlobalHub
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
IBM Security Guardium Key Lifecycle Manager (GKLM)
OpenShift Logging
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM API Connect
pam-devel
pam
pam (Red Hat package)
pam-debuginfo
pam-debugsource
pam-help
pam-doc
pam-libs
pam (Ubuntu package)
sys-libs/pam
OpenShift API for Data Protection (OADP)
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Red Hat OpenShift Container Platform
IBM Qradar SIEM

How to mitigate CVE-2024-10963

Install updates from vendor's website.

linux-pam - update to 1.7.0
Submariner - addressed in versions 0.16.8, 0.18.5
IBM Concert Software - update to 1.0.5
Guardium Data Security Center (GDSC) - addressed in versions 3.7.2, 3.8.5
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM API Connect - update to 10.0.8.5
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
IBM Observability with Instana - update to 1.0.295
Multicluster GlobalHub - update to 1.2.1
pam-devel - addressed in versions 1.3.1-36, 1.5.3-3
pam - addressed in versions 1.3.1-36, 1.5.3-3
pam (Red Hat package) - addressed in versions 1.3.1-36.el8_10, 1.5.1-22.el9_5, 1.5.1-23.el9_4
OpenShift API for Data Protection (OADP) - update to 1.4.2
pam - update to 1.5.2-9
pam-debuginfo - update to 1.5.2-9
pam-debugsource - update to 1.5.2-9
pam-devel - update to 1.5.2-9
pam-help - update to 1.5.2-9
pam-doc - update to 1.5.3-3
pam-libs - update to 1.5.3-3
pam (Ubuntu package) - addressed in versions 1.5.3-5ubuntu5.5, 1.5.3-7ubuntu4.4
pam - addressed in versions 1.6.1-5.fc40, 1.6.1-7.fc41
sys-libs/pam - update to 1.7.1
IBM Cloud Pak for Security - update to 1.11.2.0
Multicluster Engine for Kubernetes - addressed in versions 2.4.7, 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
OpenShift Service Mesh - addressed in versions 2.4.13, 2.5.7, 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.9.6, 2.10.7, 2.10.8, 2.11.4, 2.11.7, 2.12.1, 2.12.2, 2.12.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.8, 4.6.0
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.4, 4.17.1
Red Hat OpenShift Container Platform - addressed in versions 4.14.42, 4.16.25, 4.17.7
OpenShift Virtualization - update to 4.17.3
IBM Security Guardium Key Lifecycle Manager (GKLM) - update to 5.0.0 FP1
OpenShift Logging - addressed in versions 5.6.27, 5.8.16, 5.9.10
IBM QRadar Incident Forensics - update to 7.5.0 UP10 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF02
App Connect Enterprise Certified Container - update to 12.8.0
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins