Permissions, Privileges, and Access Controls in shelljs - CVE-2022-0144

 

Permissions, Privileges, and Access Controls in shelljs - CVE-2022-0144

Published: March 28, 2022


Vulnerability identifier: #VU61670
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0144
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and privilege escalation.


Affected software

shelljs
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Pak for Business Automation
Business Automation Insights
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)

How to mitigate CVE-2022-0144

Install updates from vendor's website.

shelljs - update to 0.8.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.8, 2.4.3
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20

External References

Related Security Bulletins