Cross-site scripting in pillarjs send - CVE-2024-43799

 

Cross-site scripting in pillarjs send - CVE-2024-43799

Published: September 30, 2024


Vulnerability identifier: #VU97768
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2024-43799
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the "SendStream.redirect()" function. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

pillarjs send
Argo CD
Network Observability plugin for the Openshift Console
Db2 Big SQL
Software Support app (Android)
Software Support App (iOS)
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Watson Query on Cloud Pak for Data
Maximo Application Suite - IoT Component
Maximo Application Suite - Monitor Component
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
Security QRadar EDR
Cognos Dashboards on Cloud Pak for Data
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
QRadar Log Source Management App
Business Automation Insights
IBM Cloud Pak for Security
IBM Cloud Transformation Advisor
IBM Fusion HCI
IBM Watson Knowledge Catalog in Cloud Pak for Data
Splunk User Behavior Analytics (UBA)
IBM Maximo Application Suite - Manage Component
IBM Process Mining
Qradar Advisor
Unified OSS Console Assurance Monitoring (UOCAM)
Use Case Manager App
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Decision Optimization for Cloud Pak for Data
IBM Maximo Application Suite
IBM Cloud Pak for Business Automation
IBM Observability with Instana
QRadar Suite
IBM Security QRadar Analyst Workflow
IBM Cloud Pak System
IBM Edge Application Manager
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Data
IBM QRadar Data Synchronization App
Event Streams
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift GitOps
QRadar Pulse App
watsonx.data
IBM App Connect Enterprise

How to mitigate CVE-2024-43799

Install updates from vendor's website.

pillarjs send - update to 0.19.0
Software Support app (Android) - update to 2.0.0
Software Support App (iOS) - update to 2.0.0
Data Virtualization (DV) on Cloud Pak for Data (CPD) - addressed in versions 2.2.8, 3.1.0
QRadar Suite - update to 1.10.27.0
Watson Query on Cloud Pak for Data - update to 2.2.8
IBM Cloud Transformation Advisor - update to 3.10.2
IBM Fusion HCI - update to 2.10.0
IBM Cloud Pak System - update to 2.3.6.0
Argo CD - update to 2.11.11
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Cloud Pak for Data - update to 5.2
Splunk User Behavior Analytics (UBA) - update to 5.4.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
Maximo Application Suite - IoT Component - addressed in versions 8.7.28, 8.8.24, 9.0.14, 9.1.5
Maximo Application Suite - Monitor Component - addressed in versions 8.10.15, 8.11.13, 9.0.5
Red Hat OpenShift Serverless - update to 1
Cognos Analytics Mobile (Android) - update to 1.1.21
Cognos Analytics Mobile (iOS) - update to 1.1.21
Network Observability plugin for the Openshift Console - update to 1.7.0
Migration Toolkit for Containers - update to 1.8.5
Red Hat OpenShift GitOps - addressed in versions 1.12.6, 1.13.2
IBM Process Mining - update to 2.0.0 IF001
watsonx.data - update to 2.1
QRadar Pulse App - update to 2.2.15
OpenShift Service Mesh - addressed in versions 2.4.11, 2.5.5, 2.6.2
Qradar Advisor - update to 2.6.6
IBM Security QRadar Analyst Workflow - update to 2.34.0
Unified OSS Console Assurance Monitoring (UOCAM) - update to 3.1.10
IBM QRadar Data Synchronization App - update to 3.2.1
Security QRadar EDR - update to 3.12.13
Use Case Manager App - update to 4.0.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Cognos Dashboards on Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.13, 4.15.9, 4.16.3, 4.16.5, 4.17.0, 4.17.2
Red Hat OpenShift Container Platform - update to 4.17.15
IBM Decision Optimization for Cloud Pak for Data - update to 5.1
watsonx Assistant Cartridge - update to 5.1.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.3
QRadar Log Source Management App - update to 7.0.11
IBM Maximo Application Suite - addressed in versions 8.10.19, 8.11.16, 9.0.4
Event Streams - update to 11.5.2
IBM App Connect Enterprise - update to 12.0.12.6
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
Business Automation Insights - update to 24.0.0.0.1
IBM Observability with Instana - update to 285

External References

Related Security Bulletins