Download of code without integrity check in Gin - CVE-2023-29401

 

Download of code without integrity check in Gin - CVE-2023-29401

Published: September 15, 2023


Vulnerability identifier: #VU80818
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29401
CWE-ID: CWE-494
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the system.

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote attacker with ability to perform man-in-the-middle (MitM) attack can supply a malicious software image and modify data on the system.


Affected software

Gin
Migration Toolkit for Virtualization
IBM Fusion HCI
Splunk Enterprise
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Planning Analytics Local
IBM Cloud Pak for Watson AIOps
Planning Analytics Cartridge for Cloud Pak for Data

How to mitigate CVE-2023-29401

Install updates from vendor's website.

Gin - update to 1.9.1
Migration Toolkit for Virtualization - update to 2.5.2
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Migration Toolkit for Containers - update to 1.7.11
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3
IBM Fusion HCI - update to 2.6.1
IBM Cloud Pak for Watson AIOps - update to 4.2.0
Planning Analytics Cartridge for Cloud Pak for Data - update to 4.8.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.39, 4.14.40

External References

Related Security Bulletins