Input validation error in Postcss - CVE-2023-44270

 

Input validation error in Postcss - CVE-2023-44270

Published: October 2, 2023


Vulnerability identifier: #VU81307
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44270
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to insufficient validation of external CSS files when parsing the "\r" character. A remote attacker can pass specially crafted input to the application and perform spoofing attack.


Affected software

Postcss
watsonx Orchestrate Developer Edition
Event Processing
IBM Security QRadar Network Threat Analytics
Cloud Pak for Network Automation
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Maximo Application Suite - Edge Data Collector
QRadar Suite
IBM Security QRadar Analyst Workflow
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Fusion HCI
Red Hat OpenShift Dev Spaces
Splunk Add-on for Google Cloud Platform
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Protect Plus
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
Automation Assets in IBM Cloud Pak for Integration (CP4I)
Fedora
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM QRadar Use Case Manager
jupyterlab
phpMyAdmin
python-notebook
Red Hat OpenShift Container Platform

How to mitigate CVE-2023-44270

Install updates from vendor's website.

Postcss - update to 8.4.31
watsonx Orchestrate Developer Edition - update to 1.15.0
QRadar Suite - update to 1.10.21.0
QRadar User Behavior Analytics - update to 4.1.14
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
Event Processing - update to 1.1.0
IBM Security QRadar Network Threat Analytics - update to 1.4.0
OpenShift Service Mesh - update to 2.5.7
Cloud Pak for Network Automation - update to 2.7
IBM Fusion HCI - update to 2.7.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
IBM QRadar Use Case Manager - update to 3.9.0
Red Hat OpenShift Dev Spaces - update to 3.18.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.18.0
Splunk Add-on for Google Cloud Platform - update to 4.3.0
jupyterlab - addressed in versions 4.3.2-1.fc40, 4.3.2-1.fc41, 4.3.2-1.fc42
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
Red Hat OpenShift Container Platform - addressed in versions 4.17.7, 4.17.14
phpMyAdmin - addressed in versions 5.2.2-1.fc40, 5.2.2-1.fc41
python-notebook - addressed in versions 7.3.1-1.fc40, 7.3.1-1.fc41, 7.3.1-1.fc42
Maximo Application Suite - Edge Data Collector - update to 8.11.4
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM Business Automation Workflow - addressed in versions 21.0.3 IF031, 23.0.2 IF003
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
Automation Assets in IBM Cloud Pak for Integration (CP4I) - update to 2022.2.1-14

External References

Related Security Bulletins