Server-Side Request Forgery (SSRF) in IP - CVE-2024-29415
Published: August 13, 2024 / Updated: August 23, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the isPublic() function when handling certain IP addresses, such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Note, the vulnerability exists due to incomplete fix for #VU86944 (CVE-2023-42282).
Affected software
Software Support app (Android)
Software Support App (iOS)
watsonx Orchestrate Developer Edition
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Storage Protect Plus Server
Confluence Data Center
IBM Observability with Instana
Red Hat OpenShift Dev Spaces
Bitbucket Data Center
Confluence Server
Planning Analytics Local
IBM Cognos Analytics
QRadar Pulse App
IBM Security QRadar Analyst Workflow
IBM QRadar Data Synchronization App
Bitbucket Server
How to mitigate CVE-2024-29415
Software Support App (iOS) - update to 2.0.0
watsonx Orchestrate Developer Edition - update to 1.15.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
Confluence Data Center - addressed in versions 8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2
Confluence Server - addressed in versions 8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2
IBM Observability with Instana - update to 277
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
QRadar Pulse App - update to 2.2.14
IBM Security QRadar Analyst Workflow - update to 2.33.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
IBM QRadar Data Synchronization App - update to 4.0.0
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
Storage Protect Plus Server - update to 10.1.16.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- SSRF in Fedor Indutny IP address tools for node.js
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM QRadar Pulse App
- Multiple vulnerabilities in Storage Protect Plus Server
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM Cognos Analytics
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Software Support app
- Multiple vulnerabilities in IBM watsonx Orchestrate with watsonx Assistant Cartridge
- Bitbucket Data Center and Server update for Indutny IP
- Multiple vulnerabilities in IBM watsonx Orchestrate Developer Edition
- Confluence Data Center and Server update for SSRF in indutny IP
- Multiple vulnerabilities in IBM QRadar Data Synchronization App