Input validation error in elliptic - CVE-2024-48949
Published: October 14, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input within the verify() function in lib/elliptic/eddsa/index.js. A remote attacker can send specially crafted input to the application and bypass implemented security restrictions.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Fedora
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Public Cloud Module
Python 3 Module
SUSE Package Hub 15
openSUSE Leap
DB2 Data Management Console
Storage Scale
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data
QRadar Log Source Management App
Cloud Pak for Data
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
local-npm-registry
python311-pluggy
yarnpkg
aws-cli
python311-boto3
python311-botocore
python311-pytest-metadata
python311-flaky
python311-pytest-mock
python311-pytest-html
python311-pytest-cov
grafana (Red Hat package)
python-coverage-debugsource
python311-coverage-debuginfo
python311-coverage
python311-pytest
pgadmin4-desktop
pgadmin4-web-uwsgi
pgadmin4
pgadmin4-cloud
pgadmin4-doc
system-user-pgadmin
IBM Maximo Application Suite - Manage Component
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenShift Dev Spaces
App Connect Enterprise Certified Container
Multicluster Engine for Kubernetes
How to mitigate CVE-2024-48949
DB2 Data Management Console - update to 3.1.13.2
Cloud Pak for Data - update to 5.2
Storage Scale - addressed in versions 5.2.3.7, 6.0.0.2
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.26, 8.7.20, 9.0.13
local-npm-registry - update to 1.1.0-150400.9.3.1
python311-pluggy - update to 1.5.0-150400.14.10.1
IBM Cloud Pak for Security - update to 1.11.0.0
yarnpkg - addressed in versions 1.22.22-4.fc39, 1.22.22-4.fc40, 1.22.22-4.fc41, 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41, 1.22.22-7.el8
aws-cli - update to 1.33.26-150400.34.7.1
python311-boto3 - update to 1.34.138-150400.27.7.1
python311-botocore - update to 1.34.144-150400.41.7.1
Multicluster Engine for Kubernetes - addressed in versions 2.3.8, 2.4.6
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.8, 2.9.5, 2.11.3, 2.12.0
python311-pytest-metadata - update to 3.1.1-150400.10.3.1
python311-flaky - update to 3.8.1-150400.14.6.1
python311-pytest-mock - update to 3.14.0-150400.13.6.1
Red Hat OpenShift Dev Spaces - update to 3.17.0
python311-pytest-html - update to 4.1.1-150400.10.3.1
App Connect Enterprise Certified Container - addressed in versions 5.0.18, 11.6.0, 12.0
watsonx Orchestrate Cartridge for IBM Cloud Pak for Data - update to 5.1.1
python311-pytest-cov - update to 6.2.1-150400.12.6.1
grafana (Red Hat package) - addressed in versions 6.3.6-6.el8_2, 7.3.6-8.el8_4
QRadar Log Source Management App - update to 7.0.11
python-coverage-debugsource - update to 7.6.10-150400.12.6.1
python311-coverage-debuginfo - update to 7.6.10-150400.12.6.1
python311-coverage - update to 7.6.10-150400.12.6.1
python311-pytest - update to 8.3.5-150400.3.9.1
pgadmin4-desktop - update to 8.5-150600.3.6.1
pgadmin4-web-uwsgi - update to 8.5-150600.3.6.1
pgadmin4 - update to 8.5-150600.3.6.1
pgadmin4-cloud - update to 8.5-150600.3.6.1
pgadmin4-doc - update to 8.5-150600.3.6.1
system-user-pgadmin - update to 8.5-150600.3.6.1
External References
Related Security Bulletins
- Improper input validation in Elliptic
- Fedora 40 update for yarnpkg
- Fedora 41 update for yarnpkg
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Fedora 39 update for yarnpkg
- Fedora 40 update for yarnpkg
- Fedora 41 update for yarnpkg
- Fedora 39 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Red Hat Enterprise Linux 8 update for the grafana:7.3.6 module
- Red Hat Enterprise Linux 8 update for grafana
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.9
- SUSE update for pgadmin4
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.3
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.8
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in IBM QRadar Log Source Management App
- IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data update for Elliptic
- Fedora EPEL 8 update for yarnpkg
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- IBM Cloud Pak for Data update for elliptic
- SUSE update for aws-cli, local-npm-registry, python-boto3, python-botocore, python-coverage, python-flaky, python-pluggy, python-pytest, python-pytest-cov, python-pytest-html, python-pytest-metada
- Multiple vulnerabilities in IBM DB2 Data Management Console
- Multiple vulnerabilities in IBM Storage Scale