Input validation error in nconf - CVE-2022-21803

 

Input validation error in nconf - CVE-2022-21803

Published: June 27, 2022 / Updated: June 29, 2022


Vulnerability identifier: #VU64696
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21803
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify files on the system.

The vulnerability exists due to .set() function that is responsible for setting the configuration properties is vulnerable to Prototype Pollution. A remote attacker can provide a specially crafted property, leading to prototype object pollution.


Affected software

nconf
Red Hat Advanced Cluster Management for Kubernetes
IBM Cloud Automation Manager
IBM Integration Bus
IBM App Connect Enterprise

How to mitigate CVE-2022-21803

Install update from vendor's website.

nconf - update to 0.11.4
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.10, 2.3.11, 2.4.4, 2.4.5, 2.5.0
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 7
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.5.0

External References

Related Security Bulletins