Open redirect in got - CVE-2022-33987

 

Open redirect in got - CVE-2022-33987

Published: August 11, 2022


Vulnerability identifier: #VU66400
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33987
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to requested URLs are not verified and allow open redirection to a local UNIX socket. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.

Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.


Affected software

got
IBM Engineering Requirements Quality Assistant
DB2 Data Management Console
Red Hat Software Collections
IBM App Connect Enterprise
Cloud Pak for Security (CP4S)
Event Streams
IBM Process Mining
IBM Integration Bus
IBM Cloud Pak for Business Automation
Netcool Operations Insight
Spectrum Discover
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
IBM Maximo for Civil Infrastructure
IBM Spectrum Protect Plus
IBM Robotic Process Automation
rh-nodejs14-nodejs-nodemon (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-nodejs14-nodejs (Red Hat package)
nodejs-nodemon (Red Hat package)
nodejs-nodemon
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs (Red Hat package)
nodejs-packaging
IBM Edge Application Manager
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Oracle Linux
Splunk Enterprise
Splunk Enterprise Security (ES)

How to mitigate CVE-2022-33987

Install updates from vendor's website.

got - addressed in versions 11.8.5, 12.1.0
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 1.13.1
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el7
DB2 Data Management Console - update to 3.1.13.2
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.0.3
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.5.0
rh-nodejs14-nodejs (Red Hat package) - update to 14.20.0-2.el7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Netcool Operations Insight - update to 1.6.7
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
nodejs-nodemon - update to 2.0.19-2
IBM Cloud Transformation Advisor - update to 3.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
npm - addressed in versions 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3
Splunk Enterprise Security (ES) - update to 8.1.0
IBM Maximo for Civil Infrastructure - update to 8.5.0
IBM Spectrum Protect Plus - update to 10.1.12
nodejs-docs - addressed in versions 14.20.0-2, 16.16.0-3
nodejs-full-i18n - addressed in versions 14.20.0-2, 16.16.0-3
nodejs-devel - addressed in versions 14.20.0-2, 16.16.0-3
nodejs - addressed in versions 14.20.0-2, 16.16.0-3
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
IBM Robotic Process Automation - update to 21.0.5
nodejs-packaging - addressed in versions 23-3, 25-1

External References

Related Security Bulletins