Command Injection in Node.js - CVE-2024-27980
Published: April 11, 2024
Vulnerability identifier: #VU88462
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27980
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper handling of batch files in child_process.spawn / child_process.spawnSync. An attacker can inject a malicious command line argument and achieve code execution even if the shell option is not enabled.
Affected software
Node.js
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
Rational Developer for i
Answer Retrieval for Watson Discovery On Prem
IBM Business Automation Workflow
EasyApache
Splunk User Behavior Analytics (UBA)
IBM Spectrum Symphony
Rational Application Developer
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Planning Analytics Local
IBM Cognos Controller
IBM InfoSphere Information Server
IBM App Connect Enterprise
nodejs18
nodejs18-devel
nodejs18-debugsource
npm18
nodejs18-debuginfo
nodejs18-docs
corepack18
nodejs20-devel
corepack20
nodejs20
nodejs20-debuginfo
npm20
nodejs20-debugsource
nodejs20-docs
Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
Rational Developer for i
Answer Retrieval for Watson Discovery On Prem
IBM Business Automation Workflow
EasyApache
Splunk User Behavior Analytics (UBA)
IBM Spectrum Symphony
Rational Application Developer
IBM Cloud Transformation Advisor
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Cloud Pak for Business Automation
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Fedora
Planning Analytics Local
IBM Cognos Controller
IBM InfoSphere Information Server
IBM App Connect Enterprise
nodejs18
nodejs18-devel
nodejs18-debugsource
npm18
nodejs18-debuginfo
nodejs18-docs
corepack18
nodejs20-devel
corepack20
nodejs20
nodejs20-debuginfo
npm20
nodejs20-debugsource
nodejs20-docs
How to mitigate CVE-2024-27980
Install updates from vendor's website.
Node.js - addressed in versions 18.20.2, 20.12.2, 21.7.3
EasyApache - update to 4 2024-7-10
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Spectrum Symphony - update to 7.3.2 FP3
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Answer Retrieval for Watson Discovery On Prem - update to 2.17.0
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
IBM Spectrum Control - update to 5.4.12
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM App Connect Enterprise - update to 12.0.12.5
nodejs18 - addressed in versions 18.20.2-1.fc39, 18.20.2-1.fc40
nodejs18-devel - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debugsource - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
npm18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debuginfo - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-docs - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
corepack18 - update to 18.20.4-150400.9.24.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
EasyApache - update to 4 2024-7-10
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Spectrum Symphony - update to 7.3.2 FP3
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
Answer Retrieval for Watson Discovery On Prem - update to 2.17.0
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
IBM Spectrum Control - update to 5.4.12
IBM Cognos Controller - addressed in versions 11.0.1.4, 11.1.0.2
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM App Connect Enterprise - update to 12.0.12.5
nodejs18 - addressed in versions 18.20.2-1.fc39, 18.20.2-1.fc40
nodejs18-devel - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debugsource - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
npm18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18 - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-debuginfo - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
nodejs18-docs - addressed in versions 18.20.4-8.24.1, 18.20.4-150400.9.24.2
corepack18 - update to 18.20.4-150400.9.24.2
nodejs20-devel - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
corepack20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debuginfo - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
npm20 - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-debugsource - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
nodejs20-docs - addressed in versions 20.15.1-150500.11.12.2, 20.15.1-150600.3.3.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF037, 24.0.0-IF003
External References
Related Security Bulletins
- Remote code execution in Node.js batch files
- Fedora 39 update for nodejs18
- Fedora 40 update for nodejs18
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM Answer Retrieval for Watson Discovery
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Command injection in IBM Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
- Command injection in IBM Watson Assistant for IBM Cloud Pak for Data
- SUSE update for nodejs18
- Command injection in IBM Rational Application Developer
- SUSE update for nodejs18
- SUSE update for nodejs20
- SUSE update for nodejs20
- Multiple vulnerabilities in IBM Spectrum Control
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Rational Developer for i RPG and COBOL + Modernization Tools, Java Edition
- Multiple vulnerabilities in cPanel EasyApache
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Cognos Controller
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Splunk User Behavior Analytics (UBA) update for third-party components
- Multiple vulnerabilities in IBM Spectrum Symphony