Resource exhaustion in minimist - CVE-2022-44906
Published: July 5, 2022
Vulnerability identifier: #VU64915
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-44906
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to prototype pollution in setKey() function in the index.js script. A remote attacker can send a specially-crafted request to exploit the vulnerability and execute arbitrary code on the system.
Affected software
minimist
IBM Integration Bus
IBM App Connect Enterprise
IBM Integration Bus
IBM App Connect Enterprise
How to mitigate CVE-2022-44906
Install updates from vendor's website.
minimist - update to 1.2.6
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.4.0
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.4.0