Prototype pollution in json5 - CVE-2022-46175

 

Prototype pollution in json5 - CVE-2022-46175

Published: January 26, 2023


Vulnerability identifier: #VU71577
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46175
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data within the JSON5.parse() function. A remote attacker can inject and execute arbitrary script code.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

json5
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
DB2 Data Management Console
Storage Fusion Data Foundation
Business Automation Insights
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
IBM Planning Analytics Workspace
IBM Watson Machine Learning Accelerator
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
Dell Policy Manager for Secure Connect Gateway (SCG)
gts
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
IBM Process Mining
OpenShift Logging
Confluence Data Center
Red Hat Migration Toolkit for Applications
Bitbucket Data Center
Jira Software Data Center
Jira Service Management Data Center
IBM Cloud Pak for Business Automation
Spectrum Discover
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
Splunk Enterprise Security (ES)
IBM Cloud Pak System
Red Hat Single Sign-On
Splunk Enterprise
IBM Security QRadar Analyst Workflow
Bitbucket Server
IBM App Connect Enterprise
Ubuntu
Fedora
node-json5 (Ubuntu package)
pgadmin4
rh-sso7-keycloak (Red Hat package)
Voice Gateway
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2022-46175

Install update from vendor's website.

json5 - addressed in versions 1.0.2, 2.2.2
gts - update to 4.0.1
Migration Toolkit for Containers - update to 1.7.8
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Process Mining - update to 2.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
DB2 Data Management Console - update to 3.1.13
Splunk Enterprise Security (ES) - addressed in versions 7.1.2, 7.2.0, 7.3.0
OpenShift Logging - update to 5.6.1
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.0
Red Hat Migration Toolkit for Applications - update to 6.0.1
Red Hat Single Sign-On - update to 7.6.2
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1, 9.2.8, 9.3.6, 9.4.4, 10.0.1
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
Jira Software Data Center - addressed in versions 10.3.24, 11.3.11
Jira Service Management Data Center - addressed in versions 10.3.24, 11.3.10
Business Automation Insights - addressed in versions 24.0.0.0.5, 24.0.1.0.5, 25.0.0.0.2
IBM Cloud Pak for Business Automation - addressed in versions 24.0.1-IF006, 25.0.0-IF003
node-json5 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.5.1-3ubuntu0.1
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
IBM Planning Analytics Workspace - update to 2.0.93
IBM Watson Machine Learning Accelerator - addressed in versions 2.2.6, 2.3.5, 3.1.0
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.3
IBM Fusion HCI - update to 2.6.1
IBM Security QRadar Analyst Workflow - update to 2.32.0
QRadar Deployment Intelligence App - update to 3.0.10
IBM QRadar Data Synchronization App - update to 3.1.2
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.24.0
QRadar User Behavior Analytics - update to 4.1.13
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.1.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
pgadmin4 - update to 6.19-1.fc37
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.6-1.redhat_00001.1.el7sso, 18.0.6-1.redhat_00001.1.el8sso, 18.0.6-1.redhat_00001.1.el9sso

External References

Related Security Bulletins