Server-Side Request Forgery (SSRF) in Spring Framework - CVE-2024-22243

 

Server-Side Request Forgery (SSRF) in Spring Framework - CVE-2024-22243

Published: February 21, 2024 / Updated: September 10, 2024


Vulnerability identifier: #VU86695
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-22243
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when parsing URL with the UriComponentsBuilder component. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Spring Framework
Confluence Data Center
Crowd Data Center
Bitbucket Data Center
Bamboo Server
Oracle Middleware Common Libraries and Tools
Netcool Operations Insight
Unified OSS Console Assurance Monitoring (UOCAM)
IBM Cloud Object Storage Systems
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM SPSS Collaboration and Deployment Services
IBM Security Verify Governance
IBM Business Automation Workflow
IBM Observability with Instana
Confluence Server
watsonx.data
DB2 Data Management Console
OpenPages for IBM Cloud Pak for Data
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
OpenPages Cloud pak for data service version
IBM Engineering Requirements Management DOORS Next
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
Oracle Retail Xstore Point of Service
IBM Planning Analytics Workspace
Storage Copy Data Management
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Oxygen Feedback
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Dell Policy Manager for Secure Connect Gateway (SCG)
MobileFirst Platform
Maximo Application Suite - Monitor Component
Dell Data Protection Central
Rundeck
Crowd Server
IBM Tivoli Application Dependency Discovery Manager
Web Help Desk
Juniper Secure Analytics (JSA)
QRadar Suite
Bitbucket Server
Fuse
Primavera Unifier
Bosh Release for the UAA
OpenView Performance Manager (OVPM)
Library Support for Spring
IBM Qradar SIEM
IBM Cognos Controller
Operational Decision Manager

How to mitigate CVE-2024-22243

Install updates from vendor's website.

Spring Framework - addressed in versions 5.3.32, 6.0.17, 6.1.4
Confluence Data Center - addressed in versions 7.19.23, 8.5.9, 8.9.1
Confluence Server - addressed in versions 7.19.23, 8.5.9, 8.9.1
watsonx.data - update to 2.1
DB2 Data Management Console - update to 3.1.13
OpenPages for IBM Cloud Pak for Data - update to 5.3.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.2
Rundeck - update to 4.17.5
Crowd Server - addressed in versions 5.1.11, 5.2.6, 5.3.3, 6.0.1
Crowd Data Center - addressed in versions 5.1.11, 5.2.6, 5.3.3, 6.0.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Bitbucket Data Center - addressed in versions 8.9.14, 8.19.3
Bitbucket Server - addressed in versions 8.9.14, 8.19.3
Bamboo Server - addressed in versions 9.2.12, 9.5.2
OpenPages Cloud pak for data service version - update to 9.6.0
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.11
Web Help Desk - update to 12.8.2
Bosh Release for the UAA - update to 74.5.105
OpenView Performance Manager (OVPM) - update to T0684V01^ABL
Netcool Operations Insight - update to 1.6.12
QRadar Suite - update to 1.10.22.0
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Storage Copy Data Management - update to 2.2.26.0
Cloud Pak for Network Automation - update to 2.7.5
Library Support for Spring - update to 2.7.29
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.3
IBM Cloud Object Storage Systems - addressed in versions 3.18.0.50, 3.18.2.45
IBM Cloud Pak for Watson AIOps - update to 4.5.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.4
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
Oxygen Feedback - update to 5.0 2024090417
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF03
Fuse - update to 7.13.0
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202404220901
IBM SPSS Collaboration and Deployment Services - update to 8.5.0.0.13
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.9, 8.11.6
IBM Security Verify Governance - update to 10.0.2.0.2
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
Dell Data Protection Central - update to 19.11.0-2
IBM Business Automation Workflow - addressed in versions 21.0.3 IF033, 23.0.2 IF005
IBM Observability with Instana - update to 271

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins