Insufficient verification of data authenticity in CLI - CVE-2021-43616

 

Insufficient verification of data authenticity in CLI - CVE-2021-43616

Published: May 31, 2022 / Updated: June 1, 2022


Vulnerability identifier: #VU63842
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43616
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient verification of data authenticity in the npm ci command. A remote attacker can exploit the vulnerability to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json.


Affected software

CLI
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Cloud Pak for Security (CP4S)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2021-43616

Install updates from vendor's website.

CLI - update to 8.4.1
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Cloud Pak for Watson AIOps - update to 3.5
nodejs - addressed in versions 16_epel-820220204180904.9edba152, 16.13.2-8.el7, 16.13.2-8.fc35, 16.14.0-2.el7, 16.14.0-2.fc35
nodejs - update to 18.12.1-1

External References

Related Security Bulletins