Lucene search

K
ibmIBM2AB31A2452F1029931921EB5550E825A48628AEC211877653233AD2750800450
HistoryJun 22, 2021 - 4:04 p.m.

Security Bulletin: IBM Cloud Transformation Advisor is affected by Node.js vulnerability

2021-06-2216:04:43
www.ibm.com
15
ibm cloud transformation advisor
node.js
cve-2020-28500
denial of service
upgrade

EPSS

0.002

Percentile

61.4%

Summary

IBM Cloud Transformation Advisor has addressed Node.js vulnerability CVE-2020-28500

Vulnerability Details

CVEID:CVE-2020-28500
**DESCRIPTION:**Node.js lodash module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) in the toNumber, trim and trimEnd functions. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196972 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Transformation Advisor 2.4.2, 2.4.3

Remediation/Fixes

Upgrade to 2.4.4 or later.

IBM Cloud Transformation Advisor can be installed from OperatorHub page in Red Hat OpenShift Container Platform or locally following this link.

Workarounds and Mitigations

None

EPSS

0.002

Percentile

61.4%

Related for 2AB31A2452F1029931921EB5550E825A48628AEC211877653233AD2750800450