NULL pointer dereference in ws - CVE-2024-37890
Published: July 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error when handling requests with the number of headers that exceeds the "server.maxHeadersCount" value. A remote attacker can send a specially crafted request to the application and perform a denial of service (DoS) attack.
Affected software
Astronomer with IBM
Software Support app (Android)
console
Software Support App (iOS)
Security QRadar EDR
Cognos Analytics Mobile (iOS)
Cognos Analytics Mobile (Android)
Cloud Pak for Network Automation
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Cognos Dashboards on Cloud Pak for Data
QRadar Log Source Management App
Maximo Application Suite - Monitor Component
QRadar Suite
App Connect Enterprise Certified Container
IBM Maximo Application Suite - Manage Component
IBM Observability with Instana
IBM Cloud Transformation Advisor
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
Confluence Data Center
IBM Spectrum Protect Plus
Fedora
Voice Gateway
yarnpkg
Planning Analytics Local
IBM Cloud Pak System
HPE Unified OSS Console (UOC)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Confluence Server
IBM App Connect Enterprise
How to mitigate CVE-2024-37890
Astronomer with IBM - update to 1.0.1
Software Support app (Android) - update to 2.0.0
console - update to 1.7.2
Software Support App (iOS) - update to 2.0.0
QRadar Suite - update to 1.10.25.0
Security QRadar EDR - update to 3.12.10
App Connect Enterprise Certified Container - addressed in versions 5.0.20, 12.2.0
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.27, 8.7.21, 9.0.14
IBM Observability with Instana - update to 277
Voice Gateway - addressed in versions 1.0.8.12, 1.0.8.20
Cognos Analytics Mobile (iOS) - update to 1.1.20
Cognos Analytics Mobile (Android) - update to 1.1.20
yarnpkg - addressed in versions 1.22.22-5.el9, 1.22.22-5.fc39, 1.22.22-5.fc40, 1.22.22-5.fc41
Planning Analytics Local - addressed in versions 2.0.0.99, 2.1.6
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
Cloud Pak for Network Automation - update to 2.7.5
HPE Unified OSS Console (UOC) - update to 3.1.8
IBM Cloud Transformation Advisor - update to 3.10.1
IBM Decision Optimization for Cloud Pak for Data - update to 4.8
DB2 on Cloud Pak for Data - update to 4.8.8
DB2 Warehouse on Cloud Pak for Data - update to 4.8.8
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.14.18, 4.15.14, 4.16.0, 4.16.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
Cognos Dashboards on Cloud Pak for Data - update to 5.1
QRadar Log Source Management App - update to 7.0.11
Confluence Data Center - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0
Confluence Server - addressed in versions 8.5.10, 9.2.5, 9.3.1, 9.5.1, 10.0.2, 10.1.0
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.10, 9.0.2
IBM Spectrum Protect Plus - update to 10.1.6.4
IBM App Connect Enterprise - update to 12.0.12.4
External References
- https://github.com/websockets/ws/security/advisories/GHSA-3h5v-q93c-6h6q
- https://github.com/websockets/ws/issues/2230
- https://github.com/websockets/ws/pull/2231
- https://github.com/websockets/ws/commit/22c28763234aa75a7e1b76f5c01c181260d7917f
- https://github.com/websockets/ws/commit/4abd8f6de4b0b65ef80b3ff081989479ed93377e
- https://github.com/websockets/ws/commit/e55e5106f10fcbaac37cfa89759e4cc0d073a52c
- https://github.com/websockets/ws/commit/eeb76d313e2a00dd5247ca3597bba7877d064a63
- https://nodejs.org/api/http.html#servermaxheaderscount
Related Security Bulletins
- Denial of service in WebSocket client and server for Node.js
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation
- NULL pointer dereference in IBM App Connect Enterprise
- NULL pointer dereference in IBM Voice Gateway
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in Security QRadar EDR
- NULL pointer dereference in IBM Decision Optimization for Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Multiple vulnerabilities in IBM QRadar Suite software
- IBM Watson Assistant for IBM Cloud Pak for Data update for Node.js ws module
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.16
- Fedora 40 update for yarnpkg
- Fedora 41 update for yarnpkg
- Fedora 39 update for yarnpkg
- Fedora EPEL 9 update for yarnpkg
- Minio Console update for third-party npm packages
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (Android)
- IBM Maximo Application Suite - Monitor Component update for Node.js
- Multiple vulnerabilities in IBM Cognos Analytics Mobile (iOS)
- Multiple vulnerabilities in IBM Planning Analytics
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Multiple vulnerabilities in IBM QRadar Log Source Management App
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Software Support app
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Multiple vulnerabilities in HPE Unified OSS Console Assurance Monitoring (UOCAM)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Knowledge Catalog for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- IBM Maximo Application Suite - Manage Component update for ws
- Multiple vulnerabilities in Astronomer with IBM
- Confluence Data Center and Server update for WebSockets WS