Cross-site request forgery in axios - CVE-2023-45857

 

Cross-site request forgery in axios - CVE-2023-45857

Published: October 30, 2023 / Updated: February 15, 2024


Vulnerability identifier: #VU82558
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45857
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Affected software

axios
Migration Toolkit for Containers
IBM Cloud Pak for Multicloud Management
IBM Edge Application Manager
QRadar Suite
IBM Security QRadar Analyst Workflow
Cognos Dashboards on Cloud Pak for Data
Storage Ceph
Event Processing
Storage Sentinel Anomaly Scan Engine
IBM i Modernization Engine for Lifecycle Integration
Storage Defender – Data Protect
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
QRadar Deployment Intelligence App
QRadar Assistant
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
IBM Secure External Authentication Server
Maximo Application Suite - Edge Data Collector
IBM Power 10
Voice Gateway
Migration Toolkit for Runtimes
Netcool Operations Insight
IBM Process Mining
IBM Fusion HCI
Red Hat Advanced Cluster Security for Kubernetes
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
IBM Maximo Application Suite
IBM Business Automation Workflow
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Automation Decision Services
receptor (Red Hat package)
ansible-runner (Red Hat package)
ansible-core (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
python3x-django (Red Hat package)
python-django (Red Hat package)
automation-controller (Red Hat package)
IBM QRadar Use Case Manager
OpenShift Virtualization
IBM App Connect Enterprise
IBM Cognos Analytics
Event Streams

How to mitigate CVE-2023-45857

Install updates from vendor's website.

axios - addressed in versions 0.28.0, 1.6.0
Migration Toolkit for Containers - update to 1.8.3
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Cognos Dashboards on Cloud Pak for Data - update to 5.2.2
Storage Ceph - update to 8.1
IBM Power 10 - addressed in versions FW1020.60(1020_118), FW1030.50(1030_082), FW1050.11(1050_070)
Voice Gateway - update to 1.0.8.15
Event Processing - update to 1.1.1
Storage Sentinel Anomaly Scan Engine - update to 1.1.7
Migration Toolkit for Runtimes - update to 1.2.6
receptor (Red Hat package) - addressed in versions 1.4.5-1.el8ap, 1.4.5-1.el9ap
IBM i Modernization Engine for Lifecycle Integration - update to 1.4.7
Netcool Operations Insight - update to 1.6.12
IBM Process Mining - update to 1.14.3
Storage Defender – Data Protect - update to 2.0.1
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
ansible-runner (Red Hat package) - addressed in versions 2.3.6-1.el8ap, 2.3.6-1.el9ap
Cloud Pak for Network Automation - update to 2.6.4
IBM Fusion HCI - update to 2.8.0
ansible-core (Red Hat package) - addressed in versions 2.15.10-1.el8ap, 2.15.10-1.el9ap
IBM Security QRadar Analyst Workflow - update to 2.33.1
QRadar Deployment Intelligence App - update to 3.0.13
QRadar Assistant - update to 3.6.1
IBM QRadar Use Case Manager - update to 3.9.0
python3x-aiohttp (Red Hat package) - update to 3.9.3-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.3-1.el9ap
python3x-pulpcore (Red Hat package) - update to 3.28.24-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.24-1.el9ap
python3x-django (Red Hat package) - update to 4.2.11-1.el8ap
python-django (Red Hat package) - update to 4.2.11-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.5.5-2.el8ap, 4.5.5-2.el9ap
Red Hat Advanced Cluster Security for Kubernetes - update to 4.6.0
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Virtualization - update to 4.14.6
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
IBM Secure External Authentication Server - addressed in versions 6.0.3.0 iFix 10, 6.1.0.0 iFix 06
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
IBM Maximo Application Suite - addressed in versions 8.10.8, 8.11.5
Maximo Application Suite - Edge Data Collector - update to 8.11.4
IBM App Connect Enterprise - addressed in versions 11.0.0.24, 12.0.11.0
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Event Streams - update to 11.4.0
IBM Business Automation Workflow - addressed in versions 21.0.3 IF029, 23.0.2 IF001
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5
IBM Robotic Process Automation - addressed in versions 21.0.7.13, 23.0.13
IBM Automation Decision Services - update to 23.0.1 IF006

External References

Related Security Bulletins