Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772

 

Improper Verification of Cryptographic Signature in node-forge - CVE-2022-24772

Published: August 25, 2022


Vulnerability identifier: #VU66758
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24772
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to incorrect RSA PKCS#1 v1.5 signature verification caused by a missing check or tailing garbage bytes after decoding a `DigestInfo` ASN.1 structure. A remote attacker can forge a signature and perform a man-in-the-middle (MitM) attack.


Affected software

node-forge
IBM Cloud Automation Manager
Bitbucket Data Center
Red Hat Integration - Service Registry
Red Hat Advanced Cluster Management for Kubernetes
IBM Maximo Application Suite
IBM Edge Application Manager
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Bitbucket Server
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2022-24772

Install updates from vendor's website.

node-forge - update to 1.3.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Bitbucket Data Center - update to 8.19.25
Bitbucket Server - update to 8.19.25
Red Hat Integration - Service Registry - update to 2.3.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.11.0
IBM Maximo Application Suite - addressed in versions 8.6.3, 8.7.2

External References

Related Security Bulletins