Server-Side Request Forgery (SSRF) in axios - CVE-2024-39338
Published: August 15, 2024
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Network Observability plugin for the Openshift Console
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Fedora
Python 3 Module
openSUSE Leap
IBM Concert Software
Splunk Infrastructure Monitoring Add-on
IBM Cloud Pak for Security
IBM Watson Knowledge Catalog in Cloud Pak for Data
Crowd Data Center
IBM Process Mining
IBM Fusion HCI
Unified OSS Console Assurance Monitoring (UOCAM)
Red Hat OpenShift Dev Spaces
Use Case Manager App
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Decision Optimization for Cloud Pak for Data
IBM Spectrum Control
IBM Sterling External Authentication Server
IBM Maximo Application Suite
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Observability with Instana
Event Processing
Astronomer with IBM
Software Support app (Android)
Software Support App (iOS)
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Watson Query on Cloud Pak for Data
Knowledge Catalog Premium Cartridge
Data Product Hub
QRadar Pre-Validation App
Storage Defender - Resiliency Service
Analytics Content Hub
QRadar Deployment Intelligence App
QRadar Assistant
Security QRadar EDR
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Cognos Dashboards on Cloud Pak for Data
Db2 Big SQL
Maximo Application Suite - Monitor Component
Maximo Application Suite - Edge Data Collector
Robotic Process Automation for Cloud Pak
Business Automation Insights
IBM Edge Application Manager
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Oracle GoldenGate
rust-gix-trace
rust-gix-utils
rust-gix-shallow
rust-gix-bitmap
rust-nucleo-matcher
rust-toml-span
rust-gix-command
rust-gix-chunk
rust-gix-quote
rust-nucleo
rust-gix-hashtable
rust-gix-pathspec
rust-gix-prompt
rust-gix-validate
rust-gix-sec
rust-gix-path
rust-pulldown-cmark0.11
rust-gix-dir
rust-gengo
rust-pulldown-cmark
rust-gix-ignore
rust-gix-fs
rust-gix-config-value
rust-gix-hash
rust-cargo-deny
rust-gix-status
rust-tame-index
rust-gix-submodule
rust-gix-worktree-state
rust-gix-filter
rust-gix-glob
rust-gix-negotiate
rust-gix-revwalk
rust-cargo_metadata0.18
rust-gix-packetline-blocking
rust-gix-packetline
rust-gix-archive
rust-gix-worktree-stream
rust-cargo_metadata
rust-gix-attributes
rust-gix-mailmap
rust-gix-commitgraph
rust-gix-credentials
rust-gix-refspec
rust-gix-url
rust-rustsec
rust-gix-revision
rust-gix-actor
rust-gix-index
rust-gix-discover
rust-gix-worktree
rust-gix-features
rust-gix-config
rust-gix-traverse
rust-gix-transport
rust-gix-object
rust-gix-protocol
rust-gix-diff
rust-gix-ref
rust-gix-pack
rust-gix-odb
rust-gix
rust-cargo
rust-unicode-general-category
rust-tokio
rust-tokio-macros
stgit
rust-onefetch
rust-onefetch-manifest
rust-onefetch-image
rust-onefetch-ascii
rust-dua-cli
rust-vergen
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi
rust-cargo-lock
rust-tokei12
rust-tokei
rust-gix-lock
rust-gix-tempfile
helix
nextcloud
Red Hat OpenShift Serverless
Voice Gateway
QRadar Suite
IBM Security QRadar Analyst Workflow
Planning Analytics Local
IBM API Connect
watsonx.data
IBM Cloud Pak System
IBM License Metric Tool
IBM App Connect Enterprise
How to mitigate CVE-2024-39338
IBM Concert Software - update to 2.2.0
Event Processing - update to 1.2.2
Splunk Infrastructure Monitoring Add-on - update to 1.2.7
Astronomer with IBM - update to 1.0.1
Software Support app (Android) - update to 2.0.0
Software Support App (iOS) - update to 2.0.0
Data Virtualization (DV) on Cloud Pak for Data (CPD) - addressed in versions 2.2.8, 3.1.0
Watson Query on Cloud Pak for Data - update to 2.2.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
Data Product Hub - update to 5.0.3
Crowd Data Center - addressed in versions 6.0.6, 6.1.3
rust-gix-trace - update to 0.1.12-1.fc42
rust-gix-utils - update to 0.1.14-1.fc42
rust-gix-shallow - update to 0.2.0-1.fc42
rust-gix-bitmap - update to 0.2.14-1.fc42
rust-nucleo-matcher - update to 0.3.1-1.fc42
rust-toml-span - update to 0.4.1-1.fc42
rust-gix-command - update to 0.4.1-1.fc42
rust-gix-chunk - update to 0.4.11-1.fc42
rust-gix-quote - update to 0.4.15-1.fc42
rust-nucleo - update to 0.5.0-1.fc42
rust-gix-hashtable - update to 0.7.0-1.fc42
rust-gix-pathspec - update to 0.9.0-1.fc42
rust-gix-prompt - update to 0.9.1-1.fc42
rust-gix-validate - update to 0.9.3-1.fc42
rust-gix-sec - update to 0.10.11-1.fc42
rust-gix-path - update to 0.10.14-1.fc42
rust-pulldown-cmark0.11 - update to 0.11.3-1.fc42
rust-gix-dir - update to 0.12.0-1.fc42
rust-gengo - update to 0.12.1-1.fc42
rust-pulldown-cmark - update to 0.12.2-1.fc42
rust-gix-ignore - update to 0.13.0-1.fc42
rust-gix-fs - update to 0.13.0-1.fc42
rust-gix-config-value - update to 0.14.11-1.fc42
rust-gix-hash - update to 0.16.0-1.fc42
rust-cargo-deny - update to 0.16.4-1.fc42
rust-gix-status - update to 0.17.0-1.fc42
rust-tame-index - update to 0.17.0-1.fc42
rust-gix-submodule - update to 0.17.0-1.fc42
rust-gix-worktree-state - update to 0.17.0-1.fc42
rust-gix-filter - update to 0.17.0-1.fc42
rust-gix-glob - update to 0.18.0-1.fc42
rust-gix-negotiate - update to 0.18.0-1.fc42
rust-gix-revwalk - update to 0.18.0-1.fc42
rust-cargo_metadata0.18 - update to 0.18.1-1.fc42
rust-gix-packetline-blocking - update to 0.18.2-1.fc42
rust-gix-packetline - update to 0.18.3-1.fc42
rust-gix-archive - update to 0.19.0-1.fc42
rust-gix-worktree-stream - update to 0.19.0-1.fc42
rust-cargo_metadata - update to 0.19.1-1.fc42
rust-gix-attributes - update to 0.24.0-1.fc42
rust-gix-mailmap - update to 0.25.2-1.fc42
rust-gix-commitgraph - update to 0.26.0-1.fc42
rust-gix-credentials - update to 0.27.0-1.fc42
rust-gix-refspec - update to 0.28.0-1.fc42
rust-gix-url - update to 0.29.0-1.fc42
rust-rustsec - update to 0.30.1-1.fc42
rust-gix-revision - update to 0.32.0-1.fc42
rust-gix-actor - update to 0.33.2-1.fc42
rust-gix-index - update to 0.38.0-1.fc42
rust-gix-discover - update to 0.38.0-1.fc42
rust-gix-worktree - update to 0.39.0-1.fc42
rust-gix-features - update to 0.40.0-1.fc42
rust-gix-config - update to 0.43.0-1.fc42
rust-gix-traverse - update to 0.44.0-1.fc42
rust-gix-transport - update to 0.45.0-1.fc42
rust-gix-object - update to 0.47.0-1.fc42
rust-gix-protocol - update to 0.48.0-1.fc42
rust-gix-diff - update to 0.50.0-1.fc42
rust-gix-ref - update to 0.50.0-1.fc42
rust-gix-pack - update to 0.57.0-1.fc42
rust-gix-odb - update to 0.67.0-1.fc42
rust-gix - update to 0.70.0-1.fc42
rust-cargo - update to 0.79.0-8.fc42
Red Hat OpenShift Serverless - update to 1
rust-unicode-general-category - update to 1.0.0-1.fc42
Voice Gateway - addressed in versions 1.0.8.14, 1.0.8.17, 1.0.8.22
Network Observability plugin for the Openshift Console - update to 1.7.0
Migration Toolkit for Containers - update to 1.8.4
QRadar Suite - update to 1.10.26.0
IBM Process Mining - update to 1.15.0 IF003
rust-tokio - update to 1.43.0-1.fc42
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
QRadar Pre-Validation App - update to 2.0.1
watsonx.data - update to 2.0.3
Storage Defender - Resiliency Service - update to 2.0.7
Analytics Content Hub - update to 2.3
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
rust-tokio-macros - update to 2.5.0-1.fc42
stgit - update to 2.5.1-1.fc42
IBM Fusion HCI - update to 2.9.0
rust-onefetch - update to 2.23.1-1.fc42
rust-onefetch-manifest - update to 2.23.1-1.fc42
rust-onefetch-image - update to 2.23.1-1.fc42
rust-onefetch-ascii - update to 2.23.1-1.fc42
rust-dua-cli - update to 2.29.2-3.fc42
IBM Security QRadar Analyst Workflow - update to 2.34.0
QRadar Deployment Intelligence App - update to 3.0.15
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.9
QRadar Assistant - update to 3.8.0
Security QRadar EDR - update to 3.12.13
Red Hat OpenShift Dev Spaces - update to 3.16.0
Use Case Manager App - update to 4.0.0
QRadar User Behavior Analytics - update to 4.1.17
IBM Cloud Pak for Watson AIOps - update to 4.8.1
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.0.3, 5.1.0
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
Red Hat OpenShift Container Platform - update to 4.17.4
App Connect Enterprise Certified Container - addressed in versions 5.0.22, 12.0.5, 12.4.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1
IBM Decision Optimization for Cloud Pak for Data - update to 5.1
IBM Spectrum Control - update to 5.4.13
IBM Sterling External Authentication Server - update to 6.1.0.2 ifix 01
Db2 Big SQL - update to 7.7.3
rust-vergen - update to 8.3.2-3.fc42
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
IBM Maximo Application Suite - addressed in versions 8.10.18, 8.11.15, 9.0.3
Maximo Application Suite - Monitor Component - update to 8.11.12
Maximo Application Suite - Edge Data Collector - update to 9.0.4
IBM License Metric Tool - update to 9.2.37
IBM API Connect - update to 10.0.9.0
rust-cargo-lock - update to 10.1.0-1.fc42
IBM App Connect Enterprise - update to 12.0.12.6
rust-tokei12 - update to 12.1.2-19.fc42
rust-tokei - update to 13.0.0~alpha.8-19.fc42
rust-gix-lock - update to 16.0.0-1.fc42
rust-gix-tempfile - update to 16.0.0-1.fc42
IBM Business Automation Workflow - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1.0
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
IBM Robotic Process Automation - addressed in versions 21.0.7.18, 23.0.18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.18, 23.0.18
Business Automation Insights - update to 24.0.0.0.1
helix - update to 25.01.1-1.fc42
nextcloud - addressed in versions 29.0.5-3.el9, 29.0.5-3.fc41, 29.0.5-3.fc42, 29.0.5-4.fc39, 29.0.5-4.fc40, 29.0.6-1.el9, 29.0.6-1.fc41, 29.0.6-2.fc39, 29.0.6-2.fc40
IBM Observability with Instana - update to 284
External References
Related Security Bulletins
- SSRF in axios
- Multiple vulnerabilities in IBM Storage Defender - Resiliency Service
- Fedora 42 update for nextcloud
- Fedora 39 update for nextcloud
- Fedora EPEL 9 update for nextcloud
- Fedora 41 update for nextcloud
- Fedora 40 update for nextcloud
- Fedora 41 update for nextcloud
- Fedora 40 update for nextcloud
- Fedora 39 update for nextcloud
- Fedora EPEL 9 update for nextcloud
- Multiple vulnerabilities in IBM QRadar Assistant
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Server-side request forgery in IBM License Metric Tool
- IBM watsonx.data update for Axios
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- Multiple vulnerabilities in IBM QRadar Suite Software
- Multiple vulnerabilities in IBM Data Product Hub
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- IBM Robotic Process Automation for Cloud Pak update for axios
- Multiple vulnerabilities in IBM Process Mining
- IBM Edge Application Manager update for Axios
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console 1.7
- IBM Watson Discovery update for Axios
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Maximo Application Suite
- SUSE update for pgadmin4
- IBM Maximo Application Suite - Monitor Component update for Axios
- IBM QRadar Deployment Intelligence App update for Axios
- Multiple vulnerabilities in IBM Observability with Instana
- IBM Edge Data Collector update for Axios
- Multiple vulnerabilities in IBM Security QRadar EDR
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- IBM Event Processing update for Axios
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM QRadar Pre-Validation App
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM Analytics Content Hub
- Multiple vulnerabilities in IBM Use Case Manager App
- Multiple vulnerabilities in IBM Planning Analytics
- IBM Sterling External Authentication Server update for Axios
- Multiple vulnerabilities in IBM Fusion
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- IBM Spectrum Control update for Axios
- Crowd Data Center update for axios
- Fedora 42 update for helix, rust-cargo, rust-cargo-deny, rust-cargo-lock, rust-cargo_metadata, rust-cargo_metadata0.18, rust-dua-cli, rust-gengo, rust-gix, rust-gix-actor, rust-gix-archive, rust-gix-attributes, rust-gix-bitmap, rust-gix-chunk, rust-gix-co
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- IBM Business Automation Workflow update for Axios
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- IBM Decision Optimization for Cloud Pak for Data update for Axios
- Multiple vulnerabilities in IBM Software Support app
- Multiple vulnerabilities in IBM Data Virtualization on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in Oracle GoldenGate
- Splunk Infrastructure Monitoring Add-on update for axios
- Multiple vulnerabilities in IBM Watson Knowledge Catalog
- Multiple vulnerabilities in Astronomer with IBM
- Multiple vulnerabilities in IBM Big SQL on Cloud Pak for Data
- Multiple vulnerabilities in IBM Concert Software
- Multiple vulnerabilities in IBM Knowledge Catalog Premium Cartridge