Resource exhaustion in jwcrypto - CVE-2024-28102
Published: March 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing highly compressed data within the deserialize() function. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Security QRadar EDR
IBM Watson Machine Learning Accelerator
SOAR QRadar Plugin App
QRadar Suite
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
openEuler
aap-metrics-utility (Red Hat package)
python3-jwcrypto
python-jwcrypto
python-jwcrypto (Red Hat package)
ipa-healthcheck-core
python3-pyusb
python3-yubico
python-jwcrypto-help
ansible-core (Red Hat package)
automation-controller (Red Hat package)
python3-ipalib
ipa-client
ipa-client-epn
ipa-client-samba
ipa-client-common
ipa-common
ipa-python-compat
ipa-selinux
python3-ipaclient
python3-qrcode-core
python3-qrcode
Ansible Automation Platform
How to mitigate CVE-2024-28102
QRadar Suite - update to 1.10.21.0
aap-metrics-utility (Red Hat package) - addressed in versions 0.3.0-1.el8ap, 0.3.0-1.el9ap
python3-jwcrypto - update to 0.5.0-2
python3-jwcrypto - addressed in versions 0.5.0-5, 1.4.2-3, 1.5.0-4
python-jwcrypto - addressed in versions 0.5.0-5, 1.4.2-3, 1.5.0-4
python-jwcrypto (Red Hat package) - update to 0.8-5.el9_4
ipa-healthcheck-core - update to 0.12-3
python3-pyusb - update to 1.0.0-9.1
python3-yubico - update to 1.3.2-9.1
python-jwcrypto-help - update to 1.5.0-4
Ansible Automation Platform - update to 2.4
ansible-core (Red Hat package) - addressed in versions 2.15.12-1.el8ap, 2.15.12-1.el9ap
Security QRadar EDR - update to 3.12.8
automation-controller (Red Hat package) - addressed in versions 4.5.8-1.el8ap, 4.5.8-1.el9ap
python3-ipalib - update to 4.9.13-9.0.1
ipa-client - update to 4.9.13-9.0.1
ipa-client-epn - update to 4.9.13-9.0.1
ipa-client-samba - update to 4.9.13-9.0.1
ipa-client-common - update to 4.9.13-9.0.1
ipa-common - update to 4.9.13-9.0.1
ipa-python-compat - update to 4.9.13-9.0.1
ipa-selinux - update to 4.9.13-9.0.1
python3-ipaclient - update to 4.9.13-9.0.1
IBM Watson Machine Learning Accelerator - update to 5.0.3
python3-qrcode-core - update to 5.1-12
python3-qrcode - update to 5.1-12
SOAR QRadar Plugin App - update to 5.4.0
External References
Related Security Bulletins
- Denial of service in jwcrypto
- Red Hat Enterprise Linux 9 update for python-jwcrypto
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Red Hat Enterprise Linux 8 update for the idm:DL1 and idm:client modules
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in IBM Security QRadar EDR
- openEuler 22.03 LTS SP3 update for python-jwcrypto
- openEuler 22.03 LTS SP1 update for python-jwcrypto
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- openEuler 20.03 LTS SP4 update for python-jwcrypto
- Anolis OS update for idm:client module
- openEuler 24.03 LTS SP1 update for python-jwcrypto
- openEuler 24.03 LTS update for python-jwcrypto
- openEuler 24.03 LTS SP3 update for python-jwcrypto
- openEuler 24.03 LTS SP2 update for python-jwcrypto