Resource management error in distribution - CVE-2023-2253

 

Resource management error in distribution - CVE-2023-2253

Published: May 10, 2023 / Updated: May 11, 2023


Vulnerability identifier: #VU75993
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2253
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. A remote attacker can send specially crafted requests to the "/v2/_catalog" API endpoint and perform a denial of service (DoS) attack.


Affected software

distribution
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
OpenShift API for Data Protection (OADP)
IBM Cloud Transformation Advisor
Netcool Operations Insight
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Pak for Data Scheduling
IBM Cloud Pak for Business Automation
Juniper Cloud Native Router
Red Hat OpenShift Container Platform
Dell EMC Container Storage Modules
docker-registry (Ubuntu package)
docker-distribution-registry
docker-registry (Debian package)
distribution-registry
Cloud Pak for Data
Operational Decision Manager
Junos cRPD

How to mitigate CVE-2023-2253

Install updates from vendor's website.

distribution - update to 2.8.2
OpenShift API for Data Protection (OADP) - update to 1.1.6
IBM Cloud Transformation Advisor - update to 3.10.2
Red Hat OpenShift Container Platform - addressed in versions 4.11.52, 4.12.36, 4.13.5, 4.13.13
docker-registry (Ubuntu package) - addressed in versions Ubuntu Pro, 2.7.1+ds2-7ubuntu0.3, 2.8.1+ds1-2ubuntu1.1
Netcool Operations Insight - update to 1.6.12
Dell EMC Container Storage Modules - update to 1.7.0
docker-distribution-registry - update to 2.6.2-13.9.1
docker-registry (Debian package) - update to 2.7.1+ds2-7+deb11u1
distribution-registry - addressed in versions 2.8.1-150400.9.18.1, 2.8.2-150400.9.21.1
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00
IBM Cloud Pak for Watson AIOps - update to 4.7.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.3
IBM Cloud Pak for Data Scheduling - update to 4.8.0
DB2 on Cloud Pak for Data - update to 4.8.4
Cloud Pak for Data - update to 4.8.5
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 43, 8.11.0.1 Interim fix 23, 8.11.1 Interim fix 12, 8.12.0 Interim fix 4
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.23, 23.0.1.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.7, 23.0.7
Junos cRPD - update to 23.4R1
Juniper Cloud Native Router - update to 23.4R1

External References

Related Security Bulletins