Inefficient regular expression complexity in path-to-regexp - CVE-2024-52798

 

Inefficient regular expression complexity in path-to-regexp - CVE-2024-52798

Published: December 23, 2024


Vulnerability identifier: #VU101895
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52798
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.

Affected software

path-to-regexp
watsonx.data
Support for Hyperledger Fabric
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Watson Query on Cloud Pak for Data
Cloud Pak for Network Automation
Security QRadar EDR
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Knowledge Catalog Premium Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
Watson Studio on Cloud Pak for Data
IBM OpenPages with Watson
Maximo Application Suite - IoT Component
Maximo Application Suite Ai Service
Business Automation Insights
QRadar Deployment Intelligence App
Application Modernization Accelerator
Cognos Dashboards on Cloud Pak for Data
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Telco Service Orchestrator
QRadar Log Source Management App
IBM Decision Optimization for Cloud Pak for Data
Netcool Operations Insight
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite - Manage Component
IBM Maximo Application Suite - AI Broker
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Security
Qradar Advisor
APEX Cloud Platform for Red Hat OpenShift
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Transformation Advisor
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM Cloud Pak System
IBM Edge Application Manager
Red Hat OpenShift Container Platform
IBM License Metric Tool
IBM QRadar Data Synchronization App
IBM Cognos Controller
QRadar Pulse App
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
HPE Unified OSS Console (UOC)
IBM App Connect Enterprise

How to mitigate CVE-2024-52798

Install updates from vendor's website.

path-to-regexp - update to 0.1.12
Netcool Operations Insight - update to 1.6.15
Data Virtualization (DV) on Cloud Pak for Data (CPD) - addressed in versions 2.2.8, 3.1.0
Watson Query on Cloud Pak for Data - update to 2.2.8
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.0
Cloud Pak for Network Automation - update to 2.7.8
Security QRadar EDR - update to 3.12.16
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.1.1
IBM OpenPages with Watson - addressed in versions 8.3.0.3.1, 9.0.0.5.1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
Maximo Application Suite - IoT Component - addressed in versions 8.7.28, 8.8.24, 9.0.14, 9.1.5
IBM Maximo Application Suite - AI Broker - update to 9.0.4
Maximo Application Suite Ai Service - update to 9.1.11
IBM License Metric Tool - update to 9.2.39
IBM Spectrum Protect Plus - update to 10.1.17.1
Business Automation Insights - update to 24.0.0.0.2
IBM Cloud Pak for Security - update to 1.11.2.0
watsonx.data - update to 2.1.1
QRadar Pulse App - update to 2.2.16
OpenShift Service Mesh - update to 2.5.8
Qradar Advisor - update to 2.6.6
QRadar Deployment Intelligence App - update to 3.0.16
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.13
HPE Unified OSS Console (UOC) - update to 3.1.13
IBM QRadar Data Synchronization App - update to 3.2.1
Application Modernization Accelerator - update to 4.0.1
IBM Cloud Transformation Advisor - update to 4.0.1
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.1
Cognos Dashboards on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.16.6, 4.17.3
Red Hat OpenShift Container Platform - update to 4.17.15
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
watsonx Assistant Cartridge - update to 5.1.3
Telco Service Orchestrator - update to 5.2.0
QRadar Log Source Management App - update to 7.0.11
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
App Connect Enterprise Certified Container - addressed in versions 12.0.8, 12.8.0
IBM App Connect Enterprise - addressed in versions 12.0.12.10, 13.0.2.1
IBM Cloud Pak for Business Automation - addressed in versions 24.0.0-IF004, 24.0.1-IF001

External References

Related Security Bulletins