Allocation of Resources Without Limits or Throttling in go-libp2p - CVE-2023-39533

 

Allocation of Resources Without Limits or Throttling in go-libp2p - CVE-2023-39533

Published: November 7, 2023


Vulnerability identifier: #VU82816
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39533
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

go-libp2p
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Transformation Advisor
IBM Cloud Pak for Data Scheduling
IBM Observability with Instana
IBM Business Automation Manager Open Editions
ObjectScale
Cloud Pak for Network Automation
Planning Analytics Cartridge for Cloud Pak for Data
Robotic Process Automation for Cloud Pak
Cloud Pak for Data

How to mitigate CVE-2023-39533

Install updates from vendor's website.

go-libp2p - addressed in versions 0.27.8, 0.28.2, 0.29.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.0
IBM Business Automation Manager Open Editions - update to 9.0.1
ObjectScale - update to 1.4.0
Cloud Pak for Network Automation - update to 2.7
IBM Cloud Transformation Advisor - update to 3.8.2
Planning Analytics Cartridge for Cloud Pak for Data - update to 4.8.0
IBM Cloud Pak for Data Scheduling - update to 4.8.0
Cloud Pak for Data - update to 4.8.5
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.10
IBM Observability with Instana - update to 265

External References

Related Security Bulletins