Open redirect in follow-redirects - CVE-2023-26159

 

Open redirect in follow-redirects - CVE-2023-26159

Published: January 15, 2024 / Updated: August 27, 2024


Vulnerability identifier: #VU85369
CSH Severity: Low
CVSS v4 BT: 0.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-26159
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect victims to arbitrary URL.

The vulnerability exists due to improper sanitization of user-supplied data within the url.parse() function. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.

Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.


Affected software

follow-redirects
IBM Watson Assistant for IBM Cloud Pak for Data
Migration Toolkit for Runtimes
IBM Process Mining
IBM Intelligent Operations Center
OpenShift Logging
Bitbucket Data Center
WebSphere Remote Server
IBM MQ Operator
IBM Fusion HCI
Red Hat OpenShift distributed tracing (RHOSDT)
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
Red Hat Migration Toolkit for Applications
IBM Maximo Application Suite
IBM MQ
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Automation Decision Services
Software Support App (iOS)
Security QRadar Offenses Forwarder
Software Support app (Android)
Event Processing
Rational Developer for i
IBM Security Verify Information Queue
IBM i Modernization Engine for Lifecycle Integration
QRadar Pre-Validation App
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
QRadar Assistant
DB2 on Cloud Pak for Data
Watson AI Gateway for Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Db2 Big SQL
Maximo Application Suite - Edge Data Collector
IBM MQ Appliance
Robotic Process Automation for Cloud Pak
Business Automation Insights
QRadar Suite
IBM Security QRadar Analyst Workflow
OpenShift Service Mesh
IBM Supplied MQ Advanced Queue Manager Container images
Cloud Pak for Data
IBM Cognos Controller
Event Streams
IBM Edge Application Manager
Red Hat OpenShift Container Platform
Bitbucket Server
IBM API Connect
Ubuntu
Fedora
Voice Gateway
node-follow-redirects (Ubuntu package)
pgadmin4
Network Observability plugin for the Openshift Console
IBM Cloud Pak System
IBM QRadar Use Case Manager

How to mitigate CVE-2023-26159

Install updates from vendor's website.

follow-redirects - update to 1.15.4
Software Support App (iOS) - update to 2.0.0
Security QRadar Offenses Forwarder - update to 1.2.0
Software Support app (Android) - update to 2.0.0
Event Processing - update to 1.1.5
Migration Toolkit for Runtimes - update to 1.2.4
QRadar Suite - update to 1.10.21.0
IBM Process Mining - update to 1.14.4
OpenShift Service Mesh - update to 2.5.1
Cloud Pak for Data - update to 5.2
OpenShift Logging - update to 5.8.2
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
IBM Security Verify Information Queue - update to 10.0.8
IBM API Connect - update to 10.0.8.5
IBM Cognos Controller - update to 11.0.1.0.3
Voice Gateway - update to 1.0.8.16
node-follow-redirects (Ubuntu package) - addressed in versions 1.2.4-1ubuntu0.18.04.1~esm1, 1.2.4-1ubuntu0.20.04.1~esm1, 1.14.9+~1.14.1-1ubuntu0.1~esm1
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Network Observability plugin for the Openshift Console - update to 1.5.0
QRadar Pre-Validation App - update to 2.0.1
IBM MQ Operator - addressed in versions 2.0.19, 3.1.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
IBM Cloud Pak System - update to 2.3.4.0
Cloud Pak for Network Automation - update to 2.6.5
IBM Fusion HCI - update to 2.8.0
IBM Security QRadar Analyst Workflow - update to 2.32.1
QRadar Deployment Intelligence App - update to 3.0.13
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
QRadar Assistant - update to 3.7.0
IBM QRadar Use Case Manager - update to 3.9.0
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.3
IBM Decision Optimization for Cloud Pak for Data - update to 4.8.3
DB2 on Cloud Pak for Data - update to 4.8.4
Red Hat OpenShift Container Platform - update to 4.15.0
Watson AI Gateway for Cloud Pak for Data - update to 5.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 6.2.3, 7.0.3
Db2 Big SQL - update to 7.6.2
pgadmin4 - update to 7.8-3.fc39
IBM Maximo Application Suite - addressed in versions 8.10.7, 8.11.4
Maximo Application Suite - Edge Data Collector - update to 8.11.3
IBM MQ - addressed in versions 9.2.0.22, 9.3.0.16, 9.3.5
IBM MQ Appliance - addressed in versions 9.3.0.16, 9.3.5
IBM Supplied MQ Advanced Queue Manager Container images - addressed in versions 9.3.0.16-r1, 9.3.3.3-r2, 9.3.5.0-r1
Event Streams - update to 11.4.0
IBM Business Automation Workflow - addressed in versions 21.0.3 IF029, 23.0.2 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.29, 23.0.2.1
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.16
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.16
IBM Automation Decision Services - update to 23.0.2.0.1
Business Automation Insights - update to 23.0.2.0.2

External References

Related Security Bulletins