Improper input validation in Oracle Communications Cloud Native Core Network Function Cloud Native Environment - CVE-2019-10746
Published: July 21, 2021
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Configuration (Kibana) component in Oracle Communications Cloud Native Core Network Function Cloud Native Environment. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
nodejs-mixin-deep
rh-nodejs12-nodejs-nodemon (Red Hat package)
rh-nodejs12-nodejs (Red Hat package)
How to mitigate CVE-2019-10746
rh-nodejs12-nodejs-nodemon (Red Hat package) - update to 2.0.3-1.el7
rh-nodejs12-nodejs (Red Hat package) - update to 12.20.1-1.el7
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Red Hat Software Collections update for rh-nodejs12-nodejs
- Red Hat Enterprise Linux 8 update for the nodejs:12 module
- Fedora 31 update for nodejs-mixin-deep
- Fedora 30 update for nodejs-mixin-deep