Memory leak in undici - CVE-2024-38372

 

Memory leak in undici - CVE-2024-38372

Published: July 9, 2024


Vulnerability identifier: #VU93884
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-38372
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due memory leak when using the response.arrayBuffer(). A remote attacker can force the application to leak parts of Node.js process memory.


Affected software

undici
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
Cognos Dashboards on Cloud Pak for Data

How to mitigate CVE-2024-38372

Install updates from vendor's website.

undici - update to 6.19.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
App Connect Enterprise Certified Container - addressed in versions 5.0.19, 12.0.12-r2, 12.2.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1

External References

Related Security Bulletins