Prototype pollution in qs - CVE-2022-24999
Published: November 29, 2022 / Updated: December 4, 2022
Vulnerability identifier: #VU69675
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24999
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and perform a denial of service (DoS) attack.
Affected software
qs
Express
IBM Business Automation Workflow
IBM Integration Bus
IBM Cloud Pak for Security
IBM Process Mining
Qradar Advisor
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Engineering Workflow Management
IBM Cloud Pak for Business Automation
IBM Engineering Requirements Quality Assistant
Business Automation Insights
IBM Security QRadar Network Threat Analytics
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Cloud Pak for Security (CP4S)
Event Streams
IBM QRadar Data Synchronization App
Cloud Pak for Data
QRadar Suite
Splunk Enterprise
IBM Security QRadar Analyst Workflow
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Argo CD
strapi
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
openEuler
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-qs
node-qs (Ubuntu package)
npm
nodejs
nodejs-docs
nodejs-full-i18n
nodejs-devel
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
IBM QRadar Use Case Manager
IBM App Connect Enterprise
IBM Cognos Analytics
Express
IBM Business Automation Workflow
IBM Integration Bus
IBM Cloud Pak for Security
IBM Process Mining
Qradar Advisor
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Engineering Workflow Management
IBM Cloud Pak for Business Automation
IBM Engineering Requirements Quality Assistant
Business Automation Insights
IBM Security QRadar Network Threat Analytics
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Cloud Pak for Security (CP4S)
Event Streams
IBM QRadar Data Synchronization App
Cloud Pak for Data
QRadar Suite
Splunk Enterprise
IBM Security QRadar Analyst Workflow
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Argo CD
strapi
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
openEuler
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-qs
node-qs (Ubuntu package)
npm
nodejs
nodejs-docs
nodejs-full-i18n
nodejs-devel
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
IBM QRadar Use Case Manager
IBM App Connect Enterprise
IBM Cognos Analytics
How to mitigate CVE-2022-24999
Install updates from vendor's website.
qs - addressed in versions 6.2.4, 6.3.3, 6.4.1, 6.5.3, 6.6.1, 6.7.3, 6.8.3, 6.9.7, 6.10.3
Migration Toolkit for Containers - update to 1.7.8
Cloud Pak for Security (CP4S) - update to 1.10.15.0
QRadar Suite - addressed in versions 1.10.18.0, 1.10.27.0
IBM Process Mining - update to 2.0
OpenShift Service Mesh - update to 2.2.7
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Argo CD - update to 2.4.19
Qradar Advisor - update to 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.4
Express - update to 4.17.3
strapi - update to 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.12.3
OpenShift Logging - addressed in versions 5.5.8, 5.6.3
Red Hat Migration Toolkit for Applications - update to 6.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.4
Business Automation Insights - update to 24.0.0.0.2
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-2
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
IBM Planning Analytics Workspace - update to 2.0.83
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Security QRadar Analyst Workflow - update to 2.32.0
IBM QRadar Data Synchronization App - update to 3.2.1
IBM Cloud Transformation Advisor - update to 3.4.1
IBM Cloud Pak for Watson AIOps - update to 3.7.1
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.11
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - update to 5.0.1
nodejs-qs - update to 6.5.1-2
node-qs (Ubuntu package) - update to 6.9.1+ds-1ubuntu0.1~esm1
npm - update to 6.14.17-1.14.21.1.2.0.1
Engineering Workflow Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM App Connect Enterprise - addressed in versions 11.0.0.17, 12.0.5.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2
nodejs - update to 14.21.1-2.0.1
nodejs-docs - update to 14.21.1-2.0.1
nodejs-full-i18n - update to 14.21.1-2.0.1
nodejs-devel - update to 14.21.1-2.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3
nodejs-packaging - update to 23-3
Migration Toolkit for Containers - update to 1.7.8
Cloud Pak for Security (CP4S) - update to 1.10.15.0
QRadar Suite - addressed in versions 1.10.18.0, 1.10.27.0
IBM Process Mining - update to 2.0
OpenShift Service Mesh - update to 2.2.7
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Argo CD - update to 2.4.19
Qradar Advisor - update to 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.4
Express - update to 4.17.3
strapi - update to 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.12.3
OpenShift Logging - addressed in versions 5.5.8, 5.6.3
Red Hat Migration Toolkit for Applications - update to 6.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.4
Business Automation Insights - update to 24.0.0.0.2
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-2
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
IBM Planning Analytics Workspace - update to 2.0.83
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Security QRadar Analyst Workflow - update to 2.32.0
IBM QRadar Data Synchronization App - update to 3.2.1
IBM Cloud Transformation Advisor - update to 3.4.1
IBM Cloud Pak for Watson AIOps - update to 3.7.1
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.11
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - update to 5.0.1
nodejs-qs - update to 6.5.1-2
node-qs (Ubuntu package) - update to 6.9.1+ds-1ubuntu0.1~esm1
npm - update to 6.14.17-1.14.21.1.2.0.1
Engineering Workflow Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM App Connect Enterprise - addressed in versions 11.0.0.17, 12.0.5.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2
nodejs - update to 14.21.1-2.0.1
nodejs-docs - update to 14.21.1-2.0.1
nodejs-full-i18n - update to 14.21.1-2.0.1
nodejs-devel - update to 14.21.1-2.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3
nodejs-packaging - update to 23-3
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Prototype pollution in qs
- Express update for qs
- Prototype pollution in App Connect Enterprise Certified Container
- strapi update for qs
- Red Hat Enterprise Linux 8 update for the nodejs:14 module
- Multiple vulnerabilities in argo-cd
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Planning Analytics Workspace
- Red Hat Software Collections update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon
- Prototype pollution in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.6
- Multiple vulnerabilities in IBM Business Automation Workflow Configuration Editor
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.5
- Multiple vulnerabilities in OpenShift Logging 5.6
- Prototype pollution in IBM App Connect Enterprise & IBM Integration Bus
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Prototype pollution in IBM Engineering Workflow Management (EWM)
- Prototype pollution in IBM Event Streams
- Red Hat Enterprise Linux 8.4 Extended Update Support update for the nodejs:14 module
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the nodejs:14 module
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Engineering Requirements Quality Assistant On-Premises
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.12
- Multiple vulnerabilities in IBM QRadar Advisor With Watson App for IBM QRadar SIEM
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.2
- Multiple vulnerabilities in IBM Spectrum Discover
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM QRadar Use Case Manager
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM Analyst Workflow
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management Security Services
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler 22.03 LTS SP3 update for nodejs-qs
- openEuler 20.03 LTS SP1 update for nodejs-qs
- openEuler 20.03 LTS SP4 update for nodejs-qs
- openEuler 22.03 LTS update for nodejs-qs
- openEuler 22.03 LTS SP1 update for nodejs-qs
- openEuler 22.03 LTS SP2 update for nodejs-qs
- Prototype pollution in IBM Cloud Pak for Data
- Multiple vulnerabilities in QRadar Suite Software
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Anolis OS update for nodejs:14 module
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Security QRadar Network Threat Analytics
- Ubuntu update for node-qs