Server-Side Request Forgery (SSRF) in libuv - CVE-2024-24806
Published: February 22, 2024 / Updated: February 22, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input when handling hostnames longer than 256 characters within the uv_getaddrinfo() function in src/unix/getaddrinfo.c and its windows counterpart src/win/getaddrinfo.c. A remote attacker can pass a specially crafted hostname to the application, which can be resolved to an attacker controlled IP address and initiate unauthorized requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
IBM Cloud Pak for Watson AIOps
IBM Business Automation Workflow
IBM Observability with Instana
Cryostat
Submariner
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
OpenShift Logging
Session Smart Router
Rational Application Developer
IBM Cloud Pak for Business Automation
Amazon Linux AMI
Gentoo Linux
Debian Linux
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Oracle Solaris
Chrome OS
Voice Gateway
SmartFabric Storage Software
BIG-IP
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Dell EMC VxRail Appliance
Node.js
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
libuv1 (Ubuntu package)
libuv1 (Debian package)
libuv (Red Hat package)
libuv-help
libuv-debugsource
libuv-devel
libuv
libuv-debuginfo
libuv-doc
libuv-static
libuv1-32bit-debuginfo
libuv1-64bit
libuv1-64bit-debuginfo
libuv1-32bit
libuv1
libuv1-debuginfo
dev-libs/libuv
nodejs12-debugsource
nodejs12-docs
nodejs12-debuginfo
nodejs12-devel
npm12
nodejs12
nodejs14
nodejs14-docs
npm14
nodejs14-debugsource
nodejs14-devel
nodejs14-debuginfo
npm16
nodejs16-docs
nodejs16-devel
nodejs16
nodejs16-debugsource
nodejs16-debuginfo
corepack16
nodejs18-devel
nodejs18-docs
nodejs18-debugsource
nodejs18
npm18
nodejs18-debuginfo
corepack18
nodejs20-debuginfo
nodejs20-devel
npm20
corepack20
nodejs20-debugsource
nodejs20
nodejs20-docs
Multicluster Engine for Kubernetes
IBM App Connect Enterprise
How to mitigate CVE-2024-24806
Voice Gateway - update to 1.0.8.12
IBM Observability with Instana - update to 1.0.297
SmartFabric Storage Software - update to 1.4.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Dell EMC VxRail Appliance - update to 8.321
Node.js - addressed in versions 18.19.1, 20.11.1, 21.6.2
Submariner - update to 0.18.5
Migration Toolkit for Containers - update to 1.8.5
Red Hat OpenShift GitOps - addressed in versions 1.12.5, 1.13.1
libuv1 (Ubuntu package) - addressed in versions 1.34.2-1ubuntu1.5, 1.43.0-1ubuntu0.1, 1.44.2-1ubuntu0.1
libuv1 (Debian package) - addressed in versions 1.40.0-2+deb11u1, 1.44.2-1+deb12u1
libuv (Red Hat package) - update to 1.41.1-1.el8_8.1
libuv-help - update to 1.42.0-2
libuv-debugsource - update to 1.42.0-2
libuv-devel - addressed in versions 1.42.0-2, 1.44.2-3
libuv - addressed in versions 1.42.0-2, 1.44.2-3
libuv-devel - update to 1.42.0-2
libuv-debuginfo - update to 1.42.0-2
libuv - update to 1.42.0-2
libuv-doc - update to 1.44.2-3
libuv-static - update to 1.44.2-3
libuv1-32bit-debuginfo - update to 1.44.2-150500.3.5.1
libuv1-64bit - update to 1.44.2-150500.3.5.1
libuv1-64bit-debuginfo - update to 1.44.2-150500.3.5.1
libuv1-32bit - update to 1.44.2-150500.3.5.1
libuv-devel - update to 1.44.2-150500.3.5.1
libuv-debugsource - update to 1.44.2-150500.3.5.1
libuv1 - update to 1.44.2-150500.3.5.1
libuv1-debuginfo - update to 1.44.2-150500.3.5.1
libuv - update to 1.47.0-1
libuv - update to 1.48.0
dev-libs/libuv - update to 1.48.0
Multicluster Engine for Kubernetes - addressed in versions 2.4.6, 2.5.8
IBM Cloud Transformation Advisor - update to 3.9.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.16.44, 4.17.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.21, 12.0.4, 12.4.0
OpenShift Logging - update to 5.6.21
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Rational Application Developer - update to 9.7.0.6
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.3
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
nodejs12-debugsource - update to 12.22.12-150200.4.56.1
nodejs12-docs - update to 12.22.12-150200.4.56.1
nodejs12-debuginfo - update to 12.22.12-150200.4.56.1
nodejs12-devel - update to 12.22.12-150200.4.56.1
npm12 - update to 12.22.12-150200.4.56.1
nodejs12 - update to 12.22.12-150200.4.56.1
nodejs14 - update to 14.21.3-150200.15.55.1
nodejs14-docs - update to 14.21.3-150200.15.55.1
npm14 - update to 14.21.3-150200.15.55.1
nodejs14-debugsource - update to 14.21.3-150200.15.55.1
nodejs14-devel - update to 14.21.3-150200.15.55.1
nodejs14-debuginfo - update to 14.21.3-150200.15.55.1
npm16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-docs - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-devel - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debugsource - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
corepack16 - addressed in versions 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs18-devel - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-docs - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debugsource - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
npm18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debuginfo - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
corepack18 - addressed in versions 18.19.1-150400.9.18.2, 18.20.1-150400.9.21.3
nodejs20-debuginfo - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-devel - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
npm20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
corepack20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-debugsource - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-docs - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
Chrome OS - update to 120.0.6099.310
External References
- https://github.com/libuv/libuv/security/advisories/GHSA-f74f-cvh7-c6q6
- https://github.com/libuv/libuv/commit/0f2d7e784a256b54b2385043438848047bc2a629
- https://github.com/libuv/libuv/commit/3530bcc30350d4a6ccf35d2f7b33e23292b9de70
- https://github.com/libuv/libuv/commit/c858a147643de38a09dd4164758ae5b685f2b488
- https://github.com/libuv/libuv/commit/e0327e1d508b8207c9150b6e582f0adf26213c39
- http://www.openwall.com/lists/oss-security/2024/02/08/2
- http://www.openwall.com/lists/oss-security/2024/02/11/1
Related Security Bulletins
- SSRF in libuv
- Slackware Linux update for libuv
- Multiple vulnerabilities in Node.js
- SUSE update for nodejs18
- SUSE update for nodejs20
- Ubuntu update for libuv1
- SUSE update for nodejs12
- SUSE update for nodejs14
- SUSE update for nodejs16
- SUSE update for nodejs18
- SUSE update for nodejs16
- SUSE update for nodejs16
- Multiple vulnerabilities in IBM Business Automation Workflow
- openEuler update for libuv
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- SUSE update for nodejs20
- SUSE update for nodejs18
- SUSE update for nodejs18
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in Google ChromeOS
- Multiple vulnerabilities in Rational Application Developer
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM RDi RPG and COBOL + Modernization Tools, Java Edition
- Debian update for libuv1
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.5.0
- Multiple vulnerabilities in Red Hat build of Cryostat 3 on RHEL 8
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for libuv
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Red Hat Enterprise Linux 8 update for libuv
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- SUSE update for libuv
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Gentoo update for libuv
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Anolis OS update for libuv
- Anolis OS update for libuv
- Dell SmartFabric Storage Software update for third-party components
- Dell VxRail Appliance 8.x update for third-party components
- Multiple vulnerabilities in Submariner 0.18
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- SSRF in F5 BIG-IP libuv library
- Juniper Session Smart Router update for third-party components