Deserialization of Untrusted Data in Arrow - CVE-2023-47248
Published: January 18, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized Arrow IPC, Feather or Parquet data. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
IBM Cloud Pak for Security
Oracle Financial Services Model Management and Governance
IBM Process Mining
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Application Suite
QRadar Suite
Apache Airflow
Fedora
python-geopandas
watsonx.data
Watson Studio on Cloud Pak for Data
How to mitigate CVE-2023-47248
QRadar Suite - update to 1.10.19.0
Apache Airflow - update to 2.8.1
python-geopandas - addressed in versions 0.14.1-1.fc37, 0.14.1-1.fc38, 0.14.1-1.fc39
IBM Process Mining - update to 1.14.3
watsonx.data - update to 2.0.3
Watson Studio on Cloud Pak for Data - update to 4.8.1
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
IBM Maximo Application Suite - addressed in versions 8.10.7, 8.11.4
External References
- https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n
- https://github.com/apache/arrow/commit/f14170976372436ec1d03a724d8d3f3925484ecf
- https://pypi.org/project/pyarrow-hotfix/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FR34AIPXVTMB3XPRU5ULV5HHWPMRE33X/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MAGWEAJDWO2ACYATUQCPXLSYY5C3L3XU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MWFYXLVBTBHNKYRXI572RFX7IJDDQGBL/
Related Security Bulletins
- Remote code execution in Apache Arrow
- Fedora 37 update for python-geopandas
- Fedora 38 update for python-geopandas
- Fedora 39 update for python-geopandas
- Deserialization of Untrusted Data in Apache Airflow
- Deserialization of untrusted data in IBM Watson Assistant for IBM Cloud Pak for Data
- Deserialization of untrusted data in IBM Process Mining
- Deserialization of untrusted data in IBM Maximo Application Suite - Monitor Component
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in Oracle Financial Services Model Management and Governance
- IBM watsonx.data update for PyArrow
- IBM Watson Studio on Cloud Pak for Data update for PyArrow