Prototype pollution in qs - CVE-2022-24999

 

Prototype pollution in qs - CVE-2022-24999

Published: November 29, 2022 / Updated: December 4, 2022


Vulnerability identifier: #VU69675
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24999
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted request and perform a denial of service (DoS) attack.



Affected software

qs
Express
IBM Business Automation Workflow
IBM Integration Bus
IBM Cloud Pak for Security
IBM Process Mining
Qradar Advisor
Red Hat Advanced Cluster Management for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
Spectrum Discover
IBM Cloud Pak for Multicloud Management Security Services
IBM Cloud Transformation Advisor
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Engineering Workflow Management
IBM Cloud Pak for Business Automation
IBM Engineering Requirements Quality Assistant
Business Automation Insights
IBM Security QRadar Network Threat Analytics
IBM Planning Analytics Workspace
IBM Cloud Pak for Watson AIOps
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
Cloud Pak for Security (CP4S)
Event Streams
IBM QRadar Data Synchronization App
Cloud Pak for Data
QRadar Suite
Splunk Enterprise
IBM Security QRadar Analyst Workflow
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Argo CD
strapi
Oracle Linux
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
openEuler
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
nodejs-nodemon
rh-nodejs14-nodejs-nodemon (Red Hat package)
nodejs-qs
node-qs (Ubuntu package)
npm
nodejs
nodejs-docs
nodejs-full-i18n
nodejs-devel
rh-nodejs14-nodejs (Red Hat package)
nodejs-packaging
IBM QRadar Use Case Manager
IBM App Connect Enterprise
IBM Cognos Analytics

How to mitigate CVE-2022-24999

Install updates from vendor's website.

qs - addressed in versions 6.2.4, 6.3.3, 6.4.1, 6.5.3, 6.6.1, 6.7.3, 6.8.3, 6.9.7, 6.10.3
Migration Toolkit for Containers - update to 1.7.8
Cloud Pak for Security (CP4S) - update to 1.10.15.0
QRadar Suite - addressed in versions 1.10.18.0, 1.10.27.0
IBM Process Mining - update to 2.0
OpenShift Service Mesh - update to 2.2.7
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Argo CD - update to 2.4.19
Qradar Advisor - update to 2.6.5
Red Hat Advanced Cluster Management for Kubernetes - update to 2.6.4
Express - update to 4.17.3
strapi - update to 4.5.5
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.12.3
OpenShift Logging - addressed in versions 5.5.8, 5.6.3
Red Hat Migration Toolkit for Applications - update to 6.0.1
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Event Streams - update to 11.1.4
Business Automation Insights - update to 24.0.0.0.2
IBM Security QRadar Network Threat Analytics - update to 1.4.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
nodejs-nodemon - update to 2.0.20-2
rh-nodejs14-nodejs-nodemon (Red Hat package) - update to 2.0.20-2.el7
IBM Planning Analytics Workspace - update to 2.0.83
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Security QRadar Analyst Workflow - update to 2.32.0
IBM QRadar Data Synchronization App - update to 3.2.1
IBM Cloud Transformation Advisor - update to 3.4.1
IBM Cloud Pak for Watson AIOps - update to 3.7.1
IBM QRadar Use Case Manager - update to 3.8.0
QRadar User Behavior Analytics - update to 4.1.11
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
Cloud Pak for Data - update to 4.8.5
App Connect Enterprise Certified Container - update to 5.0.1
nodejs-qs - update to 6.5.1-2
node-qs (Ubuntu package) - update to 6.9.1+ds-1ubuntu0.1~esm1
npm - update to 6.14.17-1.14.21.1.2.0.1
Engineering Workflow Management - addressed in versions 7.0.1 iFix020, 7.0.2 iFix020
IBM App Connect Enterprise - addressed in versions 11.0.0.17, 12.0.5.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 7, 11.2.4 Fix Pack 2
nodejs - update to 14.21.1-2.0.1
nodejs-docs - update to 14.21.1-2.0.1
nodejs-full-i18n - update to 14.21.1-2.0.1
nodejs-devel - update to 14.21.1-2.0.1
rh-nodejs14-nodejs (Red Hat package) - update to 14.21.1-3.el7
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.19, 22.0.2.3
nodejs-packaging - update to 23-3

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins