Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24771

 

Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24771

Published: July 25, 2022


Vulnerability identifier: #VU65749
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24771
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to a improper signature verification when checking the digestAlgorithm structure. A remote unauthenticated attacker can use a specially-crafted structure to steal padding bytes and use unchecked portion of the PKCS#1 encoded message to exploit this vulnerability and forge a signature when a low public exponent is being used.


Affected software

node-forge
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
IBM Cloud Automation Manager
Bitbucket Data Center
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Bitbucket Server
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2022-24771

Install updates from vendor's website.

node-forge - update to 1.3.0
IBM Cloud Pak for Multicloud Management - update to 2.3.5
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2

External References

Related Security Bulletins