Server-Side Request Forgery (SSRF) in libuv - CVE-2024-24806

 

Server-Side Request Forgery (SSRF) in libuv - CVE-2024-24806

Published: February 22, 2024 / Updated: February 22, 2024


Vulnerability identifier: #VU86707
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-24806
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when handling hostnames longer than 256 characters within the uv_getaddrinfo() function in src/unix/getaddrinfo.c and its windows counterpart src/win/getaddrinfo.c. A remote attacker can pass a specially crafted hostname to the application, which can be resolved to an attacker controlled IP address and initiate unauthorized requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

libuv
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
IBM Cloud Pak for Watson AIOps
IBM Business Automation Workflow
IBM Observability with Instana
Cryostat
Submariner
IBM Cloud Transformation Advisor
Red Hat OpenShift Dev Spaces
Red Hat Advanced Cluster Security for Kubernetes
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
OpenShift Logging
Session Smart Router
Rational Application Developer
IBM Cloud Pak for Business Automation
Amazon Linux AMI
Gentoo Linux
Debian Linux
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Oracle Solaris
Chrome OS
Voice Gateway
SmartFabric Storage Software
BIG-IP
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Dell EMC VxRail Appliance
Node.js
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
libuv1 (Ubuntu package)
libuv1 (Debian package)
libuv (Red Hat package)
libuv-help
libuv-debugsource
libuv-devel
libuv
libuv-debuginfo
libuv-doc
libuv-static
libuv1-32bit-debuginfo
libuv1-64bit
libuv1-64bit-debuginfo
libuv1-32bit
libuv1
libuv1-debuginfo
dev-libs/libuv
nodejs12-debugsource
nodejs12-docs
nodejs12-debuginfo
nodejs12-devel
npm12
nodejs12
nodejs14
nodejs14-docs
npm14
nodejs14-debugsource
nodejs14-devel
nodejs14-debuginfo
npm16
nodejs16-docs
nodejs16-devel
nodejs16
nodejs16-debugsource
nodejs16-debuginfo
corepack16
nodejs18-devel
nodejs18-docs
nodejs18-debugsource
nodejs18
npm18
nodejs18-debuginfo
corepack18
nodejs20-debuginfo
nodejs20-devel
npm20
corepack20
nodejs20-debugsource
nodejs20
nodejs20-docs
Multicluster Engine for Kubernetes
IBM App Connect Enterprise

How to mitigate CVE-2024-24806

Install updates from vendor's website.

libuv - update to 1.48.0
Voice Gateway - update to 1.0.8.12
IBM Observability with Instana - update to 1.0.297
SmartFabric Storage Software - update to 1.4.3
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF01
Dell EMC VxRail Appliance - update to 8.321
Node.js - addressed in versions 18.19.1, 20.11.1, 21.6.2
Submariner - update to 0.18.5
Migration Toolkit for Containers - update to 1.8.5
Red Hat OpenShift GitOps - addressed in versions 1.12.5, 1.13.1
libuv1 (Ubuntu package) - addressed in versions 1.34.2-1ubuntu1.5, 1.43.0-1ubuntu0.1, 1.44.2-1ubuntu0.1
libuv1 (Debian package) - addressed in versions 1.40.0-2+deb11u1, 1.44.2-1+deb12u1
libuv (Red Hat package) - update to 1.41.1-1.el8_8.1
libuv-help - update to 1.42.0-2
libuv-debugsource - update to 1.42.0-2
libuv-devel - addressed in versions 1.42.0-2, 1.44.2-3
libuv - addressed in versions 1.42.0-2, 1.44.2-3
libuv-devel - update to 1.42.0-2
libuv-debuginfo - update to 1.42.0-2
libuv - update to 1.42.0-2
libuv-doc - update to 1.44.2-3
libuv-static - update to 1.44.2-3
libuv1-32bit-debuginfo - update to 1.44.2-150500.3.5.1
libuv1-64bit - update to 1.44.2-150500.3.5.1
libuv1-64bit-debuginfo - update to 1.44.2-150500.3.5.1
libuv1-32bit - update to 1.44.2-150500.3.5.1
libuv-devel - update to 1.44.2-150500.3.5.1
libuv-debugsource - update to 1.44.2-150500.3.5.1
libuv1 - update to 1.44.2-150500.3.5.1
libuv1-debuginfo - update to 1.44.2-150500.3.5.1
libuv - update to 1.47.0-1
libuv - update to 1.48.0
dev-libs/libuv - update to 1.48.0
Multicluster Engine for Kubernetes - addressed in versions 2.4.6, 2.5.8
IBM Cloud Transformation Advisor - update to 3.9.0
Red Hat OpenShift Dev Spaces - update to 3.15.0
Red Hat Advanced Cluster Security for Kubernetes - update to 4.5.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.16.15, 4.16.44, 4.17.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.3
App Connect Enterprise Certified Container - addressed in versions 5.0.21, 12.0.4, 12.4.0
OpenShift Logging - update to 5.6.21
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Rational Application Developer - update to 9.7.0.6
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.3
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
nodejs12-debugsource - update to 12.22.12-150200.4.56.1
nodejs12-docs - update to 12.22.12-150200.4.56.1
nodejs12-debuginfo - update to 12.22.12-150200.4.56.1
nodejs12-devel - update to 12.22.12-150200.4.56.1
npm12 - update to 12.22.12-150200.4.56.1
nodejs12 - update to 12.22.12-150200.4.56.1
nodejs14 - update to 14.21.3-150200.15.55.1
nodejs14-docs - update to 14.21.3-150200.15.55.1
npm14 - update to 14.21.3-150200.15.55.1
nodejs14-debugsource - update to 14.21.3-150200.15.55.1
nodejs14-devel - update to 14.21.3-150200.15.55.1
nodejs14-debuginfo - update to 14.21.3-150200.15.55.1
npm16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-docs - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-devel - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debugsource - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
corepack16 - addressed in versions 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs18-devel - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-docs - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debugsource - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
npm18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debuginfo - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2, 18.20.1-8.21.1, 18.20.1-150400.9.21.3
corepack18 - addressed in versions 18.19.1-150400.9.18.2, 18.20.1-150400.9.21.3
nodejs20-debuginfo - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-devel - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
npm20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
corepack20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-debugsource - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20 - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
nodejs20-docs - addressed in versions 20.11.1-150500.11.6.1, 20.12.1-150500.11.9.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.33, 23.0.2.5
Chrome OS - update to 120.0.6099.310

External References

Related Security Bulletins