Resource exhaustion in Lodash - CVE-2019-1010266

 

Resource exhaustion in Lodash - CVE-2019-1010266

Published: July 22, 2019


Vulnerability identifier: #VU19282
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1010266
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the software does not properly parse user-supplied input in the Date Handler component. A remote authenticated attacker can send long strings that submit malicious input, which the library attempts to match using a regular expression and consume excessive amounts of CPU resources and cause a DoS condition.


Affected software

Lodash
QRadar Pulse App
IBM Watson Machine Learning Accelerator
Rational Performance Tester
DevOps Test Performance
Business Automation Insights
MobileFirst Platform
IBM Intelligent Operations Center
IBM Tivoli Netcool/OMNIbus WebGUI
IBM Cloud Pak for Business Automation
IBM Process Mining
IBM Security Verify Governance

How to mitigate CVE-2019-1010266

Install updates from vendor's website.

Lodash - update to 4.17.11
QRadar Pulse App - update to 2.2.9
IBM Watson Machine Learning Accelerator - update to 2.3.4
IBM Intelligent Operations Center - update to 5.2.4
DevOps Test Performance - update to 11.0.8
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
IBM Process Mining - update to 1.12.0.4
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Security Verify Governance - update to 10.0.1.0.5

External References

Related Security Bulletins