Server-Side Request Forgery (SSRF) in IP - CVE-2024-29415

 

Server-Side Request Forgery (SSRF) in IP - CVE-2024-29415

Published: August 13, 2024 / Updated: August 23, 2024


Vulnerability identifier: #VU95816
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-29415
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input within the isPublic() function when handling certain IP addresses, such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.

Note, the vulnerability exists due to incomplete fix for #VU86944 (CVE-2023-42282).


Affected software

IP
Software Support app (Android)
Software Support App (iOS)
watsonx Orchestrate Developer Edition
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Storage Protect Plus Server
Confluence Data Center
IBM Observability with Instana
Red Hat OpenShift Dev Spaces
Bitbucket Data Center
Confluence Server
Planning Analytics Local
IBM Cognos Analytics
QRadar Pulse App
IBM Security QRadar Analyst Workflow
IBM QRadar Data Synchronization App
Bitbucket Server

How to mitigate CVE-2024-29415

Install updates from vendor's website.

Software Support app (Android) - update to 2.0.0
Software Support App (iOS) - update to 2.0.0
watsonx Orchestrate Developer Edition - update to 1.15.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.2
Confluence Data Center - addressed in versions 8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2
Confluence Server - addressed in versions 8.5.20, 9.2.6, 9.3.1, 9.4.0, 9.5.2, 10.0.2
IBM Observability with Instana - update to 277
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
QRadar Pulse App - update to 2.2.14
IBM Security QRadar Analyst Workflow - update to 2.33.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
IBM QRadar Data Synchronization App - update to 4.0.0
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
Bitbucket Server - update to 8.19.25
Bitbucket Data Center - update to 8.19.25
Storage Protect Plus Server - update to 10.1.16.2
IBM Cognos Analytics - addressed in versions 11.2.4 FP4, 12.0.4

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins