Input validation error in Gin - CVE-2023-26125

 

Input validation error in Gin - CVE-2023-26125

Published: December 20, 2023


Vulnerability identifier: #VU84618
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26125
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to poison application's cache.

The vulnerability exists due to insufficient validation of user-supplied input when processing X-Forwarded-Prefix header. A remote attacker can pass send specially crafted request to the application and perform cache poisoning.


Affected software

Gin
Astronomer with IBM
IBM Cloud Pak for Watson AIOps
Migration Toolkit for Virtualization
Splunk Enterprise
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Planning Analytics Local

How to mitigate CVE-2023-26125

Install updates from vendor's website.

Gin - update to 1.9.0
Astronomer with IBM - update to 1.0.1
Migration Toolkit for Virtualization - update to 2.5.2
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Migration Toolkit for Containers - update to 1.7.11
Planning Analytics Local - addressed in versions 2.0.0.96, 2.1.3
IBM Cloud Pak for Watson AIOps - update to 4.1.1
Red Hat OpenShift Container Platform - addressed in versions 4.13.53, 4.13.54

External References

Related Security Bulletins