Lucene search

K
ibmIBM949B9DDB0FA651783655B4ED031BA950E0AB7E2D3614F091F8916CBB4FC837FA
HistoryNov 29, 2023 - 10:27 p.m.

Security Bulletin: IBM Event Streams is affected by a vulnerability in Node.js (CVE-2023-25883)

2023-11-2922:27:52
www.ibm.com
22
ibm event streams
node.js
vulnerability
cve-2023-25883
upgrade
version 11.3.0

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

56.2%

Summary

This security vulnerability affects a required node.js module within IBM Event Streams UI component. (CVE-2023-25883)

Vulnerability Details

CVEID:CVE-2022-25883
**DESCRIPTION:**Node.js semver package is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the new Range function. By providing specially crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/258647 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 10.0.0 - 11.2.5

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading

IBM Event Streams (Continuous Delivery)

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmevent_streamsRange10.0.0โ‰ฅ
OR
ibmevent_streamsRangeโ‰ค11.2.5
VendorProductVersionCPE
ibmevent_streams*cpe:2.3:a:ibm:event_streams:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.6

Confidence

High

EPSS

0.002

Percentile

56.2%