Open redirect in got - CVE-2022-33987
Published: August 11, 2022
Vulnerability details
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to requested URLs are not verified and allow open redirection to a local UNIX socket. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
Affected software
IBM Engineering Requirements Quality Assistant
DB2 Data Management Console
Red Hat Software Collections
IBM App Connect Enterprise
Cloud Pak for Security (CP4S)
Event Streams
IBM Process Mining
IBM Integration Bus
IBM Cloud Pak for Business Automation
Netcool Operations Insight
Spectrum Discover
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
IBM Maximo for Civil Infrastructure
IBM Spectrum Protect Plus
IBM Robotic Process Automation
rh-nodejs14-nodejs-nodemon (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rh-nodejs14-nodejs (Red Hat package)
nodejs-nodemon (Red Hat package)
nodejs-nodemon
npm
nodejs-docs
nodejs-full-i18n
nodejs-devel
nodejs
nodejs (Red Hat package)
nodejs-packaging
IBM Edge Application Manager
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Oracle Linux
Splunk Enterprise
Splunk Enterprise Security (ES)
How to mitigate CVE-2022-33987
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 1.13.1
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el7
DB2 Data Management Console - update to 3.1.13.2
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.0.3
IBM App Connect Enterprise - addressed in versions 11.0.0.18, 12.0.5.0
rh-nodejs14-nodejs (Red Hat package) - update to 14.20.0-2.el7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.11, 22.0.1.1
Netcool Operations Insight - update to 1.6.7
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon (Red Hat package) - update to 2.0.19-1.el9_0
nodejs-nodemon - update to 2.0.19-2
IBM Cloud Transformation Advisor - update to 3.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.6, 8.1.0
npm - addressed in versions 6.14.17-1.14.20.0.2, 8.11.0-1.16.16.0.3
Splunk Enterprise Security (ES) - update to 8.1.0
IBM Maximo for Civil Infrastructure - update to 8.5.0
IBM Spectrum Protect Plus - update to 10.1.12
nodejs-docs - addressed in versions 14.20.0-2, 16.16.0-3
nodejs-full-i18n - addressed in versions 14.20.0-2, 16.16.0-3
nodejs-devel - addressed in versions 14.20.0-2, 16.16.0-3
nodejs - addressed in versions 14.20.0-2, 16.16.0-3
nodejs (Red Hat package) - update to 16.16.0-1.el9_0
IBM Robotic Process Automation - update to 21.0.5
nodejs-packaging - addressed in versions 23-3, 25-1
External References
Related Security Bulletins
- Open redirect in IBM Event Streams
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Red Hat Software Collections update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon
- Red Hat Enterprise Linux 8 update for the nodejs:16 module
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Red Hat Enterprise Linux 9 update for nodejs and nodejs-nodemon
- Open redirect in IBM Robotic Process Automation
- Open redirect in IBM Process Mining
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the nodejs:14 module
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Open redirect in IBM Maximo for Civil Infrastructure in Maximo Application Suite
- IBM App Connect Enterprise Certified Container update for got
- Open redirect in IBM Edge Application Manager
- Multiple vulnerabilities in IBM Engineering Requirements Quality Assistant On-Premises
- Multiple vulnerabilities in IBM Spectrum Discover
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Anolis OS update for nodejs:14 module
- Anolis OS update for nodejs:16 module
- Splunk Enterprise Security update for third-party components
- Multiple vulnerabilities in IBM DB2 Data Management Console