Lucene search

K
ibmIBM12D335D651F1C43B3167D66E96C1D81B301767BC50D1F1D02A4F2FF83036E494
HistoryJun 26, 2024 - 6:15 a.m.

Security Bulletin: Storage Virtualize Ansible Collection is affected by a vulnerability in the Python Cryptographic Authority package

2024-06-2606:15:45
www.ibm.com
4
ibm ansible plug-in
red hat certified ansible collection
python cryptography package
cve-2024-26130
ibm storage virtualize
python version
ibm.storage_virtualize
cryptography version

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Summary

The Python cryptography package which provides both high level recipes and low level interfaces to common cryptographic algorithms such as symmetric ciphers, message digests, and key derivation functions, is used by IBM Ansible plug-in. This library is vulnerable to CVE-2024-26130.

Vulnerability Details

Refer to the security bulletin(s) listed in the Remediation/Fixes section

Affected Products and Versions

Affected Product(s) Version(s)
Red Hat Certified Ansible Collection for IBM Storage Virtualize all versions < 2.3.1

Remediation/Fixes

Update Python to version >= 3.9

Update ibm.storage_virtualize to version >= 2.3.1

Verify that cryptography >= 42.0.5 is installed. It will be installed along with ibm.storage_virtualize level listed above.

Ansible collection ibm.storage_virtualize : <https://github.com/ansible-collections/ibm.storage_virtualize&gt;

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmdocument_connect_for_application_support_facilityMatch2.3.1
CPENameOperatorVersion
ibm support for ansibleeq2.3.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.3 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%