Allocation of Resources Without Limits or Throttling in node-fetch - CVE-2020-15168
Published: May 26, 2022 / Updated: May 26, 2022
Vulnerability identifier: #VU63702
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-15168
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to node-fetch does not honor the size option after following a redirect. A remote attacker can pass specially crafted data to the application and perform a denial of service attack.
The vulnerability exists due to node-fetch does not honor the size option after following a redirect. A remote attacker can pass specially crafted data to the application and perform a denial of service attack.
Affected software
node-fetch
IBM Engineering Requirements Quality Assistant
IBM Security Risk Manager
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Planning Analytics Workspace
QRadar Assistant
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
IBM Cloud Transformation Advisor
IBM Cloud Automation Manager
IBM Intelligent Operations Center
Netcool Operations Insight
IBM Security QRadar Analyst Workflow
IBM InfoSphere Information Server
IBM Engineering Requirements Quality Assistant
IBM Security Risk Manager
Cognos Analytics Mobile (Android)
Cognos Analytics Mobile (iOS)
IBM Planning Analytics Workspace
QRadar Assistant
Cloud Pak for Security (CP4S)
IBM QRadar Data Synchronization App
IBM Cloud Transformation Advisor
IBM Cloud Automation Manager
IBM Intelligent Operations Center
Netcool Operations Insight
IBM Security QRadar Analyst Workflow
IBM InfoSphere Information Server
How to mitigate CVE-2020-15168
Install updates from vendor's website.
node-fetch - update to 2.6.1
IBM Security Risk Manager - update to 1.7.2.0
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Intelligent Operations Center - update to 5.2.4
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Netcool Operations Insight - update to 1.6.7
IBM Planning Analytics Workspace - update to 2.0.94
IBM Security QRadar Analyst Workflow - update to 2.15.1
IBM QRadar Data Synchronization App - update to 3.0.1
QRadar Assistant - update to 3.6.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
IBM Security Risk Manager - update to 1.7.2.0
Cloud Pak for Security (CP4S) - update to 1.10.15.0
IBM Intelligent Operations Center - update to 5.2.4
Cognos Analytics Mobile (Android) - update to 1.1.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Netcool Operations Insight - update to 1.6.7
IBM Planning Analytics Workspace - update to 2.0.94
IBM Security QRadar Analyst Workflow - update to 2.15.1
IBM QRadar Data Synchronization App - update to 3.0.1
QRadar Assistant - update to 3.6.0
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 1
External References
Related Security Bulletins
- Denial of service in Nicehop node-fetch for NPM
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow
- Multiple vulnerabilities in IBM QRadar Data Synchronization App
- Multiple vulnerabilities in IBM Security Risk Manager on CP4S
- Allocation of Resources Without Limits or Throttling in IBM Cloud Automation Manager
- Allocation of Resources Without Limits or Throttling in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM InfoSphere Information Server
- Multiple vulnerabilities in IBM Engineering Requirements Quality Assistant On-Premises
- Multiple vulnerabilities in IBM Intelligent Operations Center
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM QRadar Assistant