Improper Check for Unusual or Exceptional Conditions in socket.io - CVE-2024-38355

 

Improper Check for Unusual or Exceptional Conditions in socket.io - CVE-2024-38355

Published: July 23, 2024


Vulnerability identifier: #VU94660
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38355
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling. A remote attacker can send specially crafted Socket.IO packet to the application and perform a denial of service (DoS) attack.


Affected software

socket.io
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
Answer Retrieval for Watson Discovery On Prem
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi

How to mitigate CVE-2024-38355

Install updates from vendor's website.

socket.io - addressed in versions 2.5.1, 4.6.2
Answer Retrieval for Watson Discovery On Prem - update to 2.18.0
App Connect Enterprise Certified Container - addressed in versions 5.0.8, 9.0.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1

External References

Related Security Bulletins