Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24771
Published: July 25, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to a improper signature verification when checking the digestAlgorithm structure. A remote unauthenticated attacker can use a specially-crafted structure to steal padding bytes and use unchecked portion of the PKCS#1 encoded message to exploit this vulnerability and forge a signature when a low public exponent is being used.
Affected software
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
IBM Cloud Automation Manager
Bitbucket Data Center
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Bitbucket Server
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2022-24771
IBM Cloud Pak for Multicloud Management - update to 2.3.5
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2
External References
Related Security Bulletins
- Improper Verification of Cryptographic Signature in IBM Cloud Pak for Multicloud Management Managed Services
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Integration - Service registry
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Edge Application Manager
- Improper Verification of Cryptographic Signature in IBM Cloud Automation Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Bitbucket Data Center and Server update for node-forge