Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24773
Published: July 26, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. A remote unauthenticated attacker can get a successful verification with signatures that contain invalid structures but a valid digest
Affected software
IBM Cloud Automation Manager
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
IBM Edge Application Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2022-24773
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 7
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2
External References
Related Security Bulletins
- Improper Verification of Cryptographic Signature in IBM Cloud Automation Manager
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in Red Hat Integration - Service registry
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4