Command Injection in Node.js - CVE-2024-27980

 

Command Injection in Node.js - CVE-2024-27980

Published: April 11, 2024


Vulnerability identifier: #VU88462
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27980
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper handling of batch files in child_process.spawn / child_process.spawnSync. An attacker can inject a malicious command line argument and achieve code execution even if the shell option is not enabled.


Affected software

Node.js
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
Rational Developer for i
Answer Retrieval for Watson Discovery On Prem
IBM Business Automation Workflow
EasyApache
Splunk User Behavior Analytics (UBA)
IBM Spectrum Symphony
Rational Application Developer
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Planning Analytics Local
IBM Cognos Controller
IBM InfoSphere Information Server
IBM App Connect Enterprise
nodejs18
nodejs18-devel
nodejs18-debugsource
npm18
nodejs18-debuginfo
nodejs18-docs
corepack18
nodejs20-devel
corepack20
nodejs20
nodejs20-debuginfo
npm20
nodejs20-debugsource
nodejs20-docs

How to mitigate CVE-2024-27980

Install updates from vendor's website.

Node.js - addressed in versions 18.20.2, 20.12.2, 21.7.3
EasyApache - update to 4 2024-7-10
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Spectrum Symphony - update to 7.3.2 FP3
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Answer Retrieval for Watson Discovery On Prem - update to 2.17.0
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
IBM Spectrum Control - update to 5.4.12
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM App Connect Enterprise - update to 12.0.12.5
nodejs18 - addressed in versions 18.20.2-1.fc39, 18.20.2-1.fc40
nodejs18-devel - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debugsource - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
npm18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debuginfo - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-docs - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
corepack18 - update to 18.20.4-150400.9.24.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003

External References

Related Security Bulletins