Resource exhaustion in jline3 - CVE-2023-50572

 

Resource exhaustion in jline3 - CVE-2023-50572

Published: December 23, 2024


Vulnerability identifier: #VU101896
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-50572
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

jline3
IBM Application Suite - IBM Asset Data Dictionary Component
Cloudera Observability with IBM
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Object Storage Systems
IBM InfoSphere Information Server

How to mitigate CVE-2023-50572

Install updates from vendor's website.

jline3 - update to 3.26.3
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.13
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
Cloudera Observability with IBM - update to 3.6.2
IBM Cloud Object Storage Systems - addressed in versions 3.20.0.43, 3.20.0.69

External References

Related Security Bulletins