Resource exhaustion in jwcrypto - CVE-2024-28102

 

Resource exhaustion in jwcrypto - CVE-2024-28102

Published: March 7, 2024


Vulnerability identifier: #VU87180
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-28102
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing highly compressed data within the deserialize() function. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

jwcrypto
Security QRadar EDR
IBM Watson Machine Learning Accelerator
SOAR QRadar Plugin App
QRadar Suite
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
openEuler
aap-metrics-utility (Red Hat package)
python3-jwcrypto
python-jwcrypto
python-jwcrypto (Red Hat package)
ipa-healthcheck-core
python3-pyusb
python3-yubico
python-jwcrypto-help
ansible-core (Red Hat package)
automation-controller (Red Hat package)
python3-ipalib
ipa-client
ipa-client-epn
ipa-client-samba
ipa-client-common
ipa-common
ipa-python-compat
ipa-selinux
python3-ipaclient
python3-qrcode-core
python3-qrcode
Ansible Automation Platform

How to mitigate CVE-2024-28102

Install updates from vendor's website.

jwcrypto - update to 1.5.6
QRadar Suite - update to 1.10.21.0
aap-metrics-utility (Red Hat package) - addressed in versions 0.3.0-1.el8ap, 0.3.0-1.el9ap
python3-jwcrypto - update to 0.5.0-2
python3-jwcrypto - addressed in versions 0.5.0-5, 1.4.2-3, 1.5.0-4
python-jwcrypto - addressed in versions 0.5.0-5, 1.4.2-3, 1.5.0-4
python-jwcrypto (Red Hat package) - update to 0.8-5.el9_4
ipa-healthcheck-core - update to 0.12-3
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
python-jwcrypto-help - update to 1.5.0-4
Ansible Automation Platform - update to 2.4
ansible-core (Red Hat package) - addressed in versions 2.15.12-1.el8ap, 2.15.12-1.el9ap
Security QRadar EDR - update to 3.12.8
automation-controller (Red Hat package) - addressed in versions 4.5.8-1.el8ap, 4.5.8-1.el9ap
python3-ipalib - update to 4.9.13-9.0.1
ipa-client - update to 4.9.13-9.0.1
ipa-client-epn - update to 4.9.13-9.0.1
ipa-client-samba - update to 4.9.13-9.0.1
ipa-client-common - update to 4.9.13-9.0.1
ipa-common - update to 4.9.13-9.0.1
ipa-python-compat - update to 4.9.13-9.0.1
ipa-selinux - update to 4.9.13-9.0.1
python3-ipaclient - update to 4.9.13-9.0.1
IBM Watson Machine Learning Accelerator - update to 5.0.3
python3-qrcode-core - update to 5.1-12
python3-qrcode - update to 5.1-12
SOAR QRadar Plugin App - update to 5.4.0

External References

Related Security Bulletins