Uncaught Exception in engine.io - CVE-2022-41940

 

Uncaught Exception in engine.io - CVE-2022-41940

Published: June 16, 2023


Vulnerability identifier: #VU77489
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-41940
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform denial of service attacks.

The vulnerability exists due to an uncaught exception. A remote user can send specially crafted HTTP request to trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.


Affected software

engine.io
Answer Retrieval for Watson Discovery On Prem
Cloud Pak for Security (CP4S)
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
Fuse

How to mitigate CVE-2022-41940

Install updates from vendor's website.

engine.io - update to 6.2.1
Cloud Pak for Security (CP4S) - update to 1.10.8.0
Answer Retrieval for Watson Discovery On Prem - update to 2.10.0
IBM Cloud Transformation Advisor - update to 3.4.1
App Connect Enterprise Certified Container - addressed in versions 5.0.2, 6.2.0
Fuse - update to 7.12.0

External References

Related Security Bulletins