Improper access control in vm2 - CVE-2021-23555

 

Improper access control in vm2 - CVE-2021-23555

Published: December 30, 2022


Vulnerability identifier: #VU70543
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-23555
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to sandbox bypass via direct access to host error objects generated by node internals during generation of a stacktraces. A remote attacker can execute arbitrary code on the target system.


Affected software

vm2
IBM Cloud Automation Manager
Red Hat Advanced Cluster Management for Kubernetes
Cloud Pak for Multicloud Management Infrastructure Management

How to mitigate CVE-2021-23555

Install updates from vendor's website.

vm2 - update to 3.9.6
Cloud Pak for Multicloud Management Infrastructure Management - update to 2.3 Fix Pack 5
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4

External References

Related Security Bulletins