Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772
Published: August 25, 2022
Vulnerability identifier: #VU66758
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24772
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to incorrect RSA PKCS#1 v1.5 signature verification caused by a missing check or tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. A remote attacker can forge a signature and perform a man-in-the-middle (MitM) attack.
Affected software
node-forge
IBM Cloud Automation Manager
Bitbucket Data Center
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
IBM Edge Application Manager
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Bitbucket Server
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Cloud Automation Manager
Bitbucket Data Center
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
IBM Edge Application Manager
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Bitbucket Server
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2022-24772
Install updates from vendor's website.
node-forge - update to 1.3.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2
External References
Related Security Bulletins
- Improper signature verification in node-forge
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Integration - Service registry
- Multiple vulnerabilities in IBM Business Automation Manager Open Editions
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Edge Application Manager
- Improper Verification of Cryptographic Signature in IBM Cloud Automation Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in IBM DataStage on Cloud Pak for Data
- Bitbucket Data Center and Server update for node-forge