Incorrect Regular Expression in node-cross-spawn - CVE-2024-21538
Published: November 26, 2024
Vulnerability identifier: #VU100921
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21538
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Affected software
node-cross-spawn
watsonx.data
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
Web and Scripting Module
SUSE Package Hub 15
Python 3 Module
openSUSE Leap
IBM Concert Software
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Maximo Application Suite
Bitbucket Data Center
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Astronomer with IBM
watsonx Orchestrate Developer Edition
Software Support app (Android)
Cloud Pak for Network Automation
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Monitor Component
IBM Business Automation Manager Open Editions
Maximo Application Suite Ai Service
Event Processing
Security QRadar EDR
Application Modernization Accelerator
Telco Service Orchestrator
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
QRadar Log Source Management App
IBM OpenPages with Watson
IBM Event Endpoint Management
IBM Cloud Pak System
Argo CD
Cloud Pak for Data
Jira Software Server
IBM QRadar Data Synchronization App
eLabFTW
Splunk Machine Learning Toolkit
IBM App Connect Enterprise
Oracle Communications Cloud Native Core Policy
Voice Gateway
local-npm-registry
python311-pluggy
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python-coverage-debugsource
python311-coverage-debuginfo
python311-coverage
python311-pytest
npm18
nodejs18-debugsource
nodejs18-debuginfo
nodejs18-docs
nodejs18
nodejs18-devel
corepack18
nodejs20-devel
corepack20
nodejs20-debuginfo
nodejs20
nodejs20-debugsource
npm20
nodejs20-docs
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Security QRadar Analyst Workflow
HPE Unified OSS Console (UOC)
Bitbucket Server
watsonx.data
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Public Cloud Module
Web and Scripting Module
SUSE Package Hub 15
Python 3 Module
openSUSE Leap
IBM Concert Software
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
IBM Cloud Pak for Security
APEX Cloud Platform for Red Hat OpenShift
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Security for Kubernetes
IBM Maximo Application Suite
Bitbucket Data Center
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Astronomer with IBM
watsonx Orchestrate Developer Edition
Software Support app (Android)
Cloud Pak for Network Automation
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Monitor Component
IBM Business Automation Manager Open Editions
Maximo Application Suite Ai Service
Event Processing
Security QRadar EDR
Application Modernization Accelerator
Telco Service Orchestrator
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
QRadar Log Source Management App
IBM OpenPages with Watson
IBM Event Endpoint Management
IBM Cloud Pak System
Argo CD
Cloud Pak for Data
Jira Software Server
IBM QRadar Data Synchronization App
eLabFTW
Splunk Machine Learning Toolkit
IBM App Connect Enterprise
Oracle Communications Cloud Native Core Policy
Voice Gateway
local-npm-registry
python311-pluggy
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
python-coverage-debugsource
python311-coverage-debuginfo
python311-coverage
python311-pytest
npm18
nodejs18-debugsource
nodejs18-debuginfo
nodejs18-docs
nodejs18
nodejs18-devel
corepack18
nodejs20-devel
corepack20
nodejs20-debuginfo
nodejs20
nodejs20-debugsource
npm20
nodejs20-docs
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Security QRadar Analyst Workflow
HPE Unified OSS Console (UOC)
Bitbucket Server
How to mitigate CVE-2024-21538
Install update from vendor's website.
node-cross-spawn - update to 7.0.5
IBM Concert Software - update to 2.0.0
Astronomer with IBM - update to 1.0.1
watsonx Orchestrate Developer Edition - update to 2.3.0
Software Support app (Android) - update to 2.0.2
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.0
Cloud Pak for Network Automation - update to 2.7.8
Argo CD - update to 2.12.9
Guardium Data Security Center (GDSC) - update to 3.6.1
DataStage on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Cloud Pak for Data - update to 5.2
eLabFTW - update to 5.1.12
Splunk Machine Learning Toolkit - update to 5.6.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
Maximo Application Suite - Monitor Component - addressed in versions 8.10.15, 8.11.13, 9.0.5, 9.1.0
IBM Business Automation Manager Open Editions - update to 9.2.1
Maximo Application Suite Ai Service - update to 9.1.11
Jira Software Server - update to 10.3.16
Jira Software Data Center - update to 10.3.16
Jira Service Management Server - update to 10.3.16
Jira Service Management Data Center - update to 10.3.16
Voice Gateway - addressed in versions 1.0.8.15, 1.0.8.23
local-npm-registry - update to 1.1.0-150400.9.3.1
Event Processing - update to 1.3.0
python311-pluggy - update to 1.5.0-150400.14.10.1
Migration Toolkit for Containers - update to 1.8.7
IBM Cloud Pak for Security - update to 1.11.2.0
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
watsonx.data - update to 2.1.1
OpenShift Service Mesh - addressed in versions 2.4.13, 2.5.7
IBM Security QRadar Analyst Workflow - update to 2.34.0
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.12
HPE Unified OSS Console (UOC) - update to 3.1.12
IBM QRadar Data Synchronization App - update to 3.2.1
python311-flaky - update to 3.8.1-150400.14.6.1
Security QRadar EDR - update to 3.12.14
python311-pytest-mock - update to 3.14.0-150400.13.6.1
Red Hat OpenShift Dev Spaces - update to 3.18.0
Application Modernization Accelerator - update to 4.0.1
IBM Cloud Transformation Advisor - update to 4.0.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
Telco Service Orchestrator - update to 4.2.14
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.7, 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.18, 4.15.9, 4.15.14, 4.16.4, 4.16.5, 4.17.1, 4.17.2, 4.18.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.43, 4.15.40, 4.16.26, 4.17.7, 4.17.15
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
python311-pytest-cov - update to 6.2.1-150400.12.6.1
QRadar Log Source Management App - update to 7.0.11
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
IBM OpenPages with Watson - addressed in versions 8.3.0.3.1, 9.0.0.5
python311-pytest - update to 8.3.5-150400.3.9.1
IBM Maximo Application Suite - addressed in versions 8.10.21, 8.11.18, 9.0.7
Bitbucket Server - addressed in versions 8.19.16, 9.4.4
Bitbucket Data Center - addressed in versions 8.19.16, 9.4.4
IBM Event Endpoint Management - update to 11.4.2
IBM App Connect Enterprise - addressed in versions 12.0.12.9, 13.0.2.0
npm18 - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-debugsource - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-debuginfo - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-docs - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18 - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-devel - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
corepack18 - update to 18.20.5-150400.9.30.1
nodejs20-devel - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
corepack20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-debuginfo - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-debugsource - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
npm20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-docs - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Concert Software - update to 2.0.0
Astronomer with IBM - update to 1.0.1
watsonx Orchestrate Developer Edition - update to 2.3.0
Software Support app (Android) - update to 2.0.2
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.0
Cloud Pak for Network Automation - update to 2.7.8
Argo CD - update to 2.12.9
Guardium Data Security Center (GDSC) - update to 3.6.1
DataStage on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Cloud Pak for Data - update to 5.2
eLabFTW - update to 5.1.12
Splunk Machine Learning Toolkit - update to 5.6.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
Maximo Application Suite - Monitor Component - addressed in versions 8.10.15, 8.11.13, 9.0.5, 9.1.0
IBM Business Automation Manager Open Editions - update to 9.2.1
Maximo Application Suite Ai Service - update to 9.1.11
Jira Software Server - update to 10.3.16
Jira Software Data Center - update to 10.3.16
Jira Service Management Server - update to 10.3.16
Jira Service Management Data Center - update to 10.3.16
Voice Gateway - addressed in versions 1.0.8.15, 1.0.8.23
local-npm-registry - update to 1.1.0-150400.9.3.1
Event Processing - update to 1.3.0
python311-pluggy - update to 1.5.0-150400.14.10.1
Migration Toolkit for Containers - update to 1.8.7
IBM Cloud Pak for Security - update to 1.11.2.0
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
watsonx.data - update to 2.1.1
OpenShift Service Mesh - addressed in versions 2.4.13, 2.5.7
IBM Security QRadar Analyst Workflow - update to 2.34.0
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
APEX Cloud Platform for Red Hat OpenShift - addressed in versions 03.01.02.00, 03.02.04.00
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.12
HPE Unified OSS Console (UOC) - update to 3.1.12
IBM QRadar Data Synchronization App - update to 3.2.1
python311-flaky - update to 3.8.1-150400.14.6.1
Security QRadar EDR - update to 3.12.14
python311-pytest-mock - update to 3.14.0-150400.13.6.1
Red Hat OpenShift Dev Spaces - update to 3.18.0
Application Modernization Accelerator - update to 4.0.1
IBM Cloud Transformation Advisor - update to 4.0.1
python311-pytest-html - update to 4.1.1-150400.10.3.1
Telco Service Orchestrator - update to 4.2.14
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 4.4.7, 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.18, 4.15.9, 4.15.14, 4.16.4, 4.16.5, 4.17.1, 4.17.2, 4.18.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.43, 4.15.40, 4.16.26, 4.17.7, 4.17.15
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
python311-pytest-cov - update to 6.2.1-150400.12.6.1
QRadar Log Source Management App - update to 7.0.11
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
IBM OpenPages with Watson - addressed in versions 8.3.0.3.1, 9.0.0.5
python311-pytest - update to 8.3.5-150400.3.9.1
IBM Maximo Application Suite - addressed in versions 8.10.21, 8.11.18, 9.0.7
Bitbucket Server - addressed in versions 8.19.16, 9.4.4
Bitbucket Data Center - addressed in versions 8.19.16, 9.4.4
IBM Event Endpoint Management - update to 11.4.2
IBM App Connect Enterprise - addressed in versions 12.0.12.9, 13.0.2.0
npm18 - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-debugsource - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-debuginfo - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-docs - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18 - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
nodejs18-devel - addressed in versions 18.20.5-8.30.1, 18.20.5-150400.9.30.1
corepack18 - update to 18.20.5-150400.9.30.1
nodejs20-devel - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
corepack20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-debuginfo - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-debugsource - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
npm20 - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
nodejs20-docs - addressed in versions 20.18.1-150500.11.15.1, 20.18.1-150600.3.6.1
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
External References
- https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://github.com/moxystudio/node-cross-spawn/pull/160
- https://github.com/moxystudio/node-cross-spawn/commit/640d391fde65388548601d95abedccc12943374f
- https://github.com/moxystudio/node-cross-spawn/commit/5ff3a07d9add449021d806e45c4168203aa833ff
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8366349
Related Security Bulletins
- Regular expression denial of service in Moxy node-cross-spawn
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.4
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- IBM App Connect Enterprise update for package cross-spawn
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- SUSE update for nodejs18
- SUSE update for nodejs20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- SUSE update for nodejs18
- SUSE update for nodejs20
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- elabftw update for cross-spawn
- argo-cd update for node-cross-spawn
- Multiple vulnerabilities in IBM Security QRadar EDR
- IBM Voice Gateway update for cross-spawn
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.17
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in IBM QRadar Log Source Management App
- Multiple vulnerabilities in HPE Unified OSS Console (UOC) and Unified OSS Console Assurance Monitoring (UOCAM)
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM Application Modernization Accelerator
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.18
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Maximo Application Suite
- IBM Business Automation Workflow update for package cross-spawn
- IBM Maximo Application Suite - Monitor Component update for package cross-spawn
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- IBM Event Processing update for cross-spawn
- IBM watsonx.data update for cross-spawn
- Multiple vulnerabilities in IBM Event Endpoint Management
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Multiple vulnerabilities in IBM Software Support app (Android)
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for cross-spawn
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Fusion
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Splunk Machine Learning Toolkit update for third-party components
- IBM Cloud Pak for Data update for package cross-spawn
- IBM DataStage on Cloud Pak for Data update for package cross-spawn
- IBM Maximo Application Suite - Manage Component update for package cross-spawn
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for package cross-spawn
- IBM OpenPages update for package cross-spawn
- Incorrect regular expression in HPE Telco Service Orchestrator
- Multiple vulnerabilities in Astronomer with IBM
- Multiple vulnerabilities in IBM Concert Software
- SUSE update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metada
- Bitbucket Data Center and Server update for node-cross-spawn
- Jira Service Management Data Center and Server update for cross-spawn
- Jira Software Data Center and Server update for cross-spawn
- Multiple vulnerabilities in IBM Maximo AI Service
- IBM watsonx Orchestrate Developer Edition update for package cross-spawn