Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24773

 

Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24773

Published: July 26, 2022


Vulnerability identifier: #VU65780
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24773
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to signature verification code does not properly check `DigestInfo` for a proper ASN.1 structure. A remote unauthenticated attacker can get a successful verification with signatures that contain invalid structures but a valid digest


Affected software

node-forge
IBM Cloud Automation Manager
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
IBM Edge Application Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2022-24773

Install updates from vendor's website.

node-forge - update to 1.3.0
IBM Cloud Automation Manager - update to 4.2.0.1 iFix 7
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2

External References

Related Security Bulletins