Lucene search

K
ibmIBM1DB8F8D66D935AEB31DE6EAE3FD318B3DE382428C92D264F59F07AB7D395F483
HistoryAug 13, 2024 - 10:06 a.m.

Security Bulletin: IBM Instana Observability is vulnerable to AuthZ Plugin Bypass and Privilege Escalation

2024-08-1310:06:34
www.ibm.com
9
ibm instana observability
authz plugin bypass
privilege escalation
cve-2024-41110
docker engine
authorization validation
security restrictions
vulnerability
build 278
build 279
remediation
ibm docs

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

6.5

Confidence

Low

Summary

Vulnerability in Docker Engine that could allow attackers to bypass authorization plugins (AuthZ) was remediated in IBM Observability with Instana Build 279. (CVE-2024-41110)

Vulnerability Details

CVEID:CVE-2024-41110
**DESCRIPTION:**Moby could allow a remote authenticated attacker to bypass security restrictions, caused by improper authorization validation. By sending a specially crafted API request, an attacker could exploit this vulnerability to bypass authorization plugins (AuthZ).
CVSS Base score: 9.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/350495 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Observability with Instana (OnPrem) Build 278

Remediation/Fixes

IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here:

<https://www.ibm.com/docs/en/instana-observability/current&gt;

Affected Product(s) Version(s) Remediation/Fixes/Instructions
IBM Observability with Instana (OnPrem) Build 278 Build 279

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmobservability_with_instanaMatch272
OR
ibmobservability_with_instanaMatch278
VendorProductVersionCPE
ibmobservability_with_instana272cpe:2.3:a:ibm:observability_with_instana:272:*:*:*:*:*:*:*
ibmobservability_with_instana278cpe:2.3:a:ibm:observability_with_instana:278:*:*:*:*:*:*:*

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

6.5

Confidence

Low