Inefficient regular expression complexity in AngularJS - CVE-2023-26117

 

Inefficient regular expression complexity in AngularJS - CVE-2023-26117

Published: August 10, 2023


Vulnerability identifier: #VU79318
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26117
CWE-ID: CWE-1333
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient input validation when processing untrusted input passed via the $resource service. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.


Affected software

AngularJS
IBM Business Automation Manager Open Editions
IBM OpenPages with Watson
IBM MQ Appliance
Storage Protect Plus Server
IBM App Connect Enterprise
BIG-IP
Fedora
HPE Unified OSS Console (UOC)
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Tivoli Business Service Manager
IBM Tivoli Netcool Impact
IBM MQ
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
icecat

How to mitigate CVE-2023-26117

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

IBM Business Automation Manager Open Editions - update to 8.0.8
IBM App Connect Enterprise - update to 12.0.9.0
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.1
IBM Tivoli Business Service Manager - update to 6.2.0.4
IBM Tivoli Netcool Impact - update to 7.1.0.31
IBM OpenPages with Watson - addressed in versions 8.3.0.2.7, 9.0.0.1
IBM MQ - update to 9.3.0
IBM MQ Appliance - update to 9.3.0.0
IBM Spectrum Protect Plus - update to 10.1.6.4
Storage Protect Plus Server - update to 10.1.16.3
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
icecat - addressed in versions 115.3.1-7.rh2.fc38, 115.3.1-7.rh2.fc39

External References

Related Security Bulletins