Prototype pollution in requirejs - CVE-2024-38998

 

Prototype pollution in requirejs - CVE-2024-38998

Published: September 13, 2024


Vulnerability identifier: #VU97243
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38998
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary JavaScript code.

The vulnerability exists due to prototype pollution via the function config. A remote attacker can pass specially crafted input to the application and perform prototype pollution, which can result in arbitrary code execution or denial of service (DoS).


Affected software

requirejs
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Python 3 Module
openSUSE Leap
IBM Process Mining
IBM Watson Discovery for IBM Cloud Pak for Data
Planning Analytics Local
Cognos Dashboards on Cloud Pak for Data
Business Automation Insights
pgadmin4-desktop
system-user-pgadmin
pgadmin4-doc
pgadmin4-cloud
pgadmin4
pgadmin4-web-uwsgi

How to mitigate CVE-2024-38998

Install update from vendor's website.

requirejs - update to 2.3.7
IBM Process Mining - update to 2.0
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
Business Automation Insights - update to 24.0.0.0.1

External References

Related Security Bulletins