Incorrect Regular Expression in Luxon - CVE-2023-22467

 

Incorrect Regular Expression in Luxon - CVE-2023-22467

Published: February 7, 2023


Vulnerability identifier: #VU72033
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22467
CWE-ID: CWE-185
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an incorrect regular expression when parsing untrusted input within the Luxon's DateTime.fromRFC2822() function. A remote attacker can causes a noticeable slowdown for inputs with lengths above 10k characters.

Note, this is the same vulnerability as #VU65835 (CVE-2022-31129) reported earlier for moment.js.


Affected software

Luxon
IBM Cloud Pak for Watson AIOps
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
Dell Policy Manager for Secure Connect Gateway (SCG)
Robotic Process Automation for Cloud Pak
Fedora
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Red Hat Advanced Cluster Management for Kubernetes
App Connect Enterprise Certified Container
IBM Maximo Asset Management
IBM Robotic Process Automation
python-nikola

How to mitigate CVE-2023-22467

Install updates from vendor's website.

Luxon - addressed in versions 1.28.1, 2.5.2, 3.2.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-5
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Red Hat Advanced Cluster Management for Kubernetes - update to 2.7.0
App Connect Enterprise Certified Container - addressed in versions 5.0.3, 7.1.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
IBM Maximo Asset Management - addressed in versions 8.1.10, 9.0.6
python-nikola - addressed in versions 8.3.0-1.fc38, 8.3.0-1.fc39
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
IBM Robotic Process Automation - addressed in versions 21.0.7.3, 23.0.3

External References

Related Security Bulletins