Input validation error in Postcss - CVE-2023-44270
Published: October 2, 2023
Vulnerability identifier: #VU81307
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44270
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insufficient validation of external CSS files when parsing the "\r" character. A remote attacker can pass specially crafted input to the application and perform spoofing attack.
Affected software
Postcss
watsonx Orchestrate Developer Edition
Event Processing
IBM Security QRadar Network Threat Analytics
Cloud Pak for Network Automation
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Maximo Application Suite - Edge Data Collector
QRadar Suite
IBM Security QRadar Analyst Workflow
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
Splunk Add-on for Google Cloud Platform
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Fedora
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM QRadar Use Case Manager
jupyterlab
phpMyAdmin
python-notebook
Red Hat OpenShift Container Platform
watsonx Orchestrate Developer Edition
Event Processing
IBM Security QRadar Network Threat Analytics
Cloud Pak for Network Automation
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Maximo Application Suite - Edge Data Collector
QRadar Suite
IBM Security QRadar Analyst Workflow
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
Splunk Add-on for Google Cloud Platform
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Fedora
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM QRadar Use Case Manager
jupyterlab
phpMyAdmin
python-notebook
Red Hat OpenShift Container Platform
How to mitigate CVE-2023-44270
Install updates from vendor's website.
Postcss - update to 8.4.31
watsonx Orchestrate Developer Edition - update to 1.15.0
QRadar Suite - update to 1.10.21.0
QRadar User Behavior Analytics - update to 4.1.14
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
Event Processing - update to 1.1.0
IBM Security QRadar Network Threat Analytics - update to 1.4.0
OpenShift Service Mesh - update to 2.5.7
Cloud Pak for Network Automation - update to 2.7
IBM Fusion HCI - update to 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
IBM QRadar Use Case Manager - update to 3.9.0
Red Hat OpenShift Dev Spaces - update to 3.18.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.18.0
Splunk Add-on for Google Cloud Platform - update to 4.3.0
jupyterlab - addressed in versions 4.3.2-1.fc40, 4.3.2-1.fc41, 4.3.2-1.fc42
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Red Hat OpenShift Container Platform - addressed in versions 4.17.7, 4.17.14
phpMyAdmin - addressed in versions 5.2.2-1.fc40, 5.2.2-1.fc41
python-notebook - addressed in versions 7.3.1-1.fc40, 7.3.1-1.fc41, 7.3.1-1.fc42
Maximo Application Suite - Edge Data Collector - update to 8.11.4
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Business Automation Workflow - addressed in versions 21.0.3 IF031, 23.0.2 IF003
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
watsonx Orchestrate Developer Edition - update to 1.15.0
QRadar Suite - update to 1.10.21.0
QRadar User Behavior Analytics - update to 4.1.14
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
Event Processing - update to 1.1.0
IBM Security QRadar Network Threat Analytics - update to 1.4.0
OpenShift Service Mesh - update to 2.5.7
Cloud Pak for Network Automation - update to 2.7
IBM Fusion HCI - update to 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
IBM QRadar Use Case Manager - update to 3.9.0
Red Hat OpenShift Dev Spaces - update to 3.18.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.18.0
Splunk Add-on for Google Cloud Platform - update to 4.3.0
jupyterlab - addressed in versions 4.3.2-1.fc40, 4.3.2-1.fc41, 4.3.2-1.fc42
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Red Hat OpenShift Container Platform - addressed in versions 4.17.7, 4.17.14
phpMyAdmin - addressed in versions 5.2.2-1.fc40, 5.2.2-1.fc41
python-notebook - addressed in versions 7.3.1-1.fc40, 7.3.1-1.fc41, 7.3.1-1.fc42
Maximo Application Suite - Edge Data Collector - update to 8.11.4
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Business Automation Workflow - addressed in versions 21.0.3 IF031, 23.0.2 IF003
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14
External References
Related Security Bulletins
- Improper input validation in PostCSS
- Multiple vulnerabilities in IBM Storage Fusion
- Multiple vulnerabilities in Splunk Add-on for Google Cloud Platform
- IBM Watson Discovery Cartridge for IBM Cloud Pak for Data update for PostCSS
- Automation Assets in IBM Cloud Pak for Integration update for PostCSS
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Input validation error in IBM Event Processing
- Multiple vulnerabilities in IBM QRadar Use Case Manager
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Input validation error in IBM Edge Data Collector
- Input validation error in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Analyst Workflow
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Fedora 42 update for jupyterlab, python-notebook
- Fedora 41 update for jupyterlab, python-notebook
- Fedora 40 update for jupyterlab, python-notebook
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.18
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.18
- Fedora 41 update for phpMyAdmin
- Fedora 40 update for phpMyAdmin
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Security QRadar Network Threat Analytics
- IBM watsonx Orchestrate Developer Edition update for PostCSS