Path traversal in Moment - CVE-2022-24785

 

Path traversal in Moment - CVE-2022-24785

Published: April 20, 2022


Vulnerability identifier: #VU62463
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24785
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within the npm version of Moment.js. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Moment
IBM VM Recovery Manager HA GUI
IBM VM Recovery Manager DR
B2B Advanced Communications
IBM Watson Machine Learning Accelerator
Tivoli Network Manager IP Edition
Storage Fusion Data Foundation
IBM Business Automation Manager Open Editions
IBM i Modernization Engine for Lifecycle Integration
Storage Copy Data Management
QRadar Deployment Intelligence App
Storage Ceph
Tenable.sc
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
IBM Spectrum Protect for Space Management
IBM QRadar DNS Analyzer App
IBM Edge Application Manager
Nessus Network Monitor
IBM Spectrum Protect Backup-Archive Client
IBM Process Mining
Red Hat Advanced Cluster Management for Kubernetes
IBM Db2 Mirror for i
Confluence Data Center
Tenable Nessus
Netcool Operations Insight
Spectrum Discover
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Guardium Data Encryption (GDE)
IBM Watson Discovery for IBM Cloud Pak for Data
QRadar User Behavior Analytics
IBM Maximo Asset Management
IBM Maximo Application Suite
Bitbucket Data Center
IBM Spectrum Protect Plus
Ceph
Automation Assets in IBM Cloud Pak for Integration (CP4I)
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
servicemesh-proxy (Red Hat package)
servicemesh (Red Hat package)
servicemesh-cni (Red Hat package)
servicemesh-operator (Red Hat package)
servicemesh-ratelimit (Red Hat package)
servicemesh-prometheus (Red Hat package)
python-dataclasses (Red Hat package)
python-werkzeug (Red Hat package)
libjs-moment (Ubuntu package)
node-moment (Ubuntu package)
ceph-iscsi (Red Hat package)
ceph-ansible (Red Hat package)
python-notebook
rh-sso7-keycloak (Red Hat package)
IBM Data Risk Manager
Cloudera Data Platform Private Cloud Base for IBM
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
JBoss Enterprise Application Platform
Fuse
Bitbucket Server
Red Hat Single Sign-On
Confluence Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Ubuntu
Fedora
concrete5
Ghost
Siebel Core - Common Components
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
Jazz Reporting Service
IBM Cloud Pak System
IBM Storage Scale System
Red Hat Ceph Storage
Engineering Lifecycle Management

How to mitigate CVE-2022-24785

Install update from vendor's website.

Moment - update to 2.29.2
Tenable.sc - update to 5.21.0
IBM QRadar DNS Analyzer App - update to 2.0.1
B2B Advanced Communications - update to 1.0.0.12
IBM Process Mining - update to 1.13.1
OpenShift Service Mesh - addressed in versions 2.0.11, 2.1.3, 2.1.5
servicemesh-proxy (Red Hat package) - addressed in versions 2.0.11-1.el8, 2.1.5-1.el8
servicemesh (Red Hat package) - addressed in versions 2.0.11-1.el8, 2.1.5-1.el8
servicemesh-cni (Red Hat package) - update to 2.0.11-1.el8
servicemesh-operator (Red Hat package) - addressed in versions 2.0.11-1.el8, 2.1.5-1.el8
IBM Data Risk Manager - update to 2.0.6.15
servicemesh-ratelimit (Red Hat package) - update to 2.1.5-1.el8
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.10, 2.3.11, 2.4.4, 2.4.5, 2.5.0
servicemesh-prometheus (Red Hat package) - update to 2.23.0-9.el8
Tivoli Network Manager IP Edition - update to 4.2.0.20
Nessus Network Monitor - update to 6.2.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
JBoss Enterprise Application Platform - update to 7.4.5
Red Hat Single Sign-On - update to 7.6.2
Fuse - addressed in versions 7.11.1, 7.12.0
Confluence Data Center - addressed in versions 7.19.26, 8.0.0
Confluence Server - addressed in versions 7.19.26, 8.0.0
IBM Business Automation Manager Open Editions - update to 8.0.1
concrete5 - update to 9.2.0
Tenable Nessus - update to 10.3.1
python-dataclasses (Red Hat package) - update to 0.8-3.el8cp
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Netcool Operations Insight - update to 1.6.6
Cloud Pak for Security (CP4S) - update to 1.10.14.0
python-werkzeug (Red Hat package) - update to 2.0.3-3.el8cp
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
Storage Copy Data Management - update to 2.2.26.0
IBM Cloud Pak System - update to 2.3.3.7 iFix 01
Red Hat OpenShift distributed tracing (RHOSDT) - update to 2.6.0
IBM Guardium Data Encryption (GDE) - update to 2.6.7
libjs-moment (Ubuntu package) - addressed in versions 2.20.1+ds-1ubuntu0.1, 2.24.0+ds-2ubuntu0.1, 2.29.1+ds-3ubuntu0.2
node-moment (Ubuntu package) - addressed in versions 2.20.1+ds-1ubuntu0.1, 2.24.0+ds-2ubuntu0.1, 2.29.1+ds-3ubuntu0.2
QRadar Deployment Intelligence App - update to 3.0.10
IBM QRadar Data Synchronization App - update to 3.1.1
ceph-iscsi (Red Hat package) - update to 3.6-1.el8cp
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.0.9
QRadar User Behavior Analytics - update to 4.1.9
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
Ghost - addressed in versions 4.48.2, 5.2.3
IBM Storage Scale System - addressed in versions 5.2.0.0, 6.1.9.2
ceph-ansible (Red Hat package) - update to 6.0.28.3-1.el8cp
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1
python-notebook - addressed in versions 6.4.0-4.fc35, 6.4.11-3.fc36, 6.4.11-3.fc37, 7.0.0-1.fc39
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
Jazz Reporting Service - update to 7.0.2 iFix021
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9 SP1
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.26, 7.6.1.3.0.1, 8.1.10, 9.0.6
IBM Spectrum Protect Backup-Archive Client - update to 8.1.17.2
IBM Spectrum Protect for Space Management - update to 8.1.17.2
IBM Maximo Application Suite - update to 8.4.3
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
IBM Spectrum Protect Plus - update to 10.1.14
Ceph - addressed in versions 16.2.10-94.el8cp, 16.2.10-94.el9cp
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.6-1.redhat_00001.1.el7sso, 18.0.6-1.redhat_00001.1.el8sso, 18.0.6-1.redhat_00001.1.el9sso
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2020.4.1-6, 2021.4.1-4

External References

Related Security Bulletins