Improper access control in Webpack - CVE-2023-28154
Published: April 5, 2023
Vulnerability identifier: #VU74478
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28154
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions on cross-realm objects in ImportParserPlugin.js. A remote attacker who controls a property of an untrusted object can obtain access to the real global object.
Affected software
Webpack
IBM Watson Assistant for IBM Cloud Pak for Data
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Edge Application Manager
SecureTransport
Fedora
pcs (Red Hat package)
pcs
IBM Cloud Pak System
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
IBM Watson Assistant for IBM Cloud Pak for Data
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Edge Application Manager
SecureTransport
Fedora
pcs (Red Hat package)
pcs
IBM Cloud Pak System
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
How to mitigate CVE-2023-28154
Install updates from vendor's website.
Webpack - update to 5.76.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.5
SecureTransport - update to 5.5-20230629
pcs (Red Hat package) - update to 0.11.3-4.el9_1.3
pcs - addressed in versions 0.11.5-2.fc36, 0.11.5-2.fc37, 0.11.5-2.fc38
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.6
IBM Cloud Pak for Watson AIOps - update to 3.7.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-8, 2022.4.1-3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.5
SecureTransport - update to 5.5-20230629
pcs (Red Hat package) - update to 0.11.3-4.el9_1.3
pcs - addressed in versions 0.11.5-2.fc36, 0.11.5-2.fc37, 0.11.5-2.fc38
IBM Cloud Pak System - update to 2.3.3.6 iFix 1
Cloud Pak for Network Automation - update to 2.4.6
IBM Cloud Pak for Watson AIOps - update to 3.7.1
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-7
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 2022.2.1-8, 2022.4.1-3
External References
Related Security Bulletins
- Improper access control in Webpack
- Red Hat Enterprise Linux 9 update for pcs
- Improper access control in Platform Navigator and Automation Assets in IBM Cloud Pak for Integration
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Improper access control in IBM Edge Application Manager
- Improper access control in IBM Watson Assistant for Cloud pak for Data
- Multiple vulnerabilities in Axway SecureTransport
- Fedora 38 update for pcs
- Fedora 37 update for pcs
- Fedora 36 update for pcs
- Multiple vulnerabilities in IBM Cloud Pak System