Improper Neutralization of Argument Delimiters in a Command in tqdm - CVE-2024-34062

 

Improper Neutralization of Argument Delimiters in a Command in tqdm - CVE-2024-34062

Published: May 3, 2024


Vulnerability identifier: #VU89133
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-34062
CWE-ID: CWE-88
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromsie the target system.

The vulnerability exists due to an argument injection issue. A local user can execute arbitrary code on the target system.


Affected software

tqdm
QRadar App SDK
Security QRadar EDR
IBM Cloud Pak for Watson AIOps
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
IBM Process Mining
IBM Watson Assistant for IBM Cloud Pak for Data
Python for Scientific Computing
openEuler
Ubuntu
Anolis OS
Fedora
python3-tqdm (Ubuntu package)
python3-tqdm
python-tqdm-help
python-tqdm
python3-tqdm-doc
Splunk Add-on for Cisco Meraki
IBM InfoSphere Information Server

How to mitigate CVE-2024-34062

Install updates from vendor's website.

tqdm - update to 4.66.3
IBM Process Mining - update to 1.15.0
Python for Scientific Computing - update to 4.2.1
python3-tqdm (Ubuntu package) - update to Ubuntu Pro
Splunk Add-on for Cisco Meraki - update to 2.2.0
QRadar App SDK - update to 2.2.2
Security QRadar EDR - update to 3.12.9
IBM Cloud Pak for Watson AIOps - update to 4.6.0
python3-tqdm - update to 4.56.0-4
python-tqdm-help - update to 4.56.0-4
python-tqdm - update to 4.56.0-4
python3-tqdm-doc - update to 4.65.0-3
python3-tqdm - update to 4.65.0-3
python-tqdm - addressed in versions 4.66.4-2.fc38, 4.66.4-2.fc39, 4.66.4-2.fc40
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.1
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5

External References

Related Security Bulletins