Uncaught Exception in socket.io-parser - CVE-2023-32695
Published: July 21, 2023
Vulnerability identifier: #VU78488
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-32695
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling. A remote attacker can send a specially crafted Socket.IO packet to the application and perform a denial of service (DoS) attack.
Affected software
socket.io-parser
Splunk User Behavior Analytics (UBA)
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
Dell Data Protection Central
IBM Planning Analytics Workspace
Storage Protect Plus Server
HPE Unified OSS Console (UOC)
Splunk User Behavior Analytics (UBA)
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
Dell Data Protection Central
IBM Planning Analytics Workspace
Storage Protect Plus Server
HPE Unified OSS Console (UOC)
How to mitigate CVE-2023-32695
Install updates from vendor's website.
socket.io-parser - update to 4.2.3
Splunk User Behavior Analytics (UBA) - addressed in versions 5.2.1, 5.3.0
Dell Data Protection Central - update to 19.12.0-2
IBM Planning Analytics Workspace - update to 2.0.94
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 8.2.0
Storage Protect Plus Server - update to 10.1.16.3
Splunk User Behavior Analytics (UBA) - addressed in versions 5.2.1, 5.3.0
Dell Data Protection Central - update to 19.12.0-2
IBM Planning Analytics Workspace - update to 2.0.94
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 8.2.0
Storage Protect Plus Server - update to 10.1.16.3
External References
- https://github.com/socketio/socket.io-parser/releases/tag/4.2.3
- https://github.com/socketio/socket.io-parser/commit/3b78117bf6ba7e99d7a5cfc1ba54d0477554a7f3
- https://github.com/socketio/socket.io-parser/commit/2dc3c92622dad113b8676be06f23b1ed46b02ced
- https://github.com/socketio/socket.io-parser/security/advisories/GHSA-cqmj-92xf-r6r9
Related Security Bulletins
- Multiple vulnerabilities in IBM Watson Knowledge Catalog for IBM Cloud Pak for Data
- Uncaught exception in IBM App Connect Enterprise Certified Container
- Splunk User Behavior Analytics (UBA) update for third-party software
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Storage Protect Plus
- Dell Data Protection Central update for third-party component
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)