Lucene search

K
ibmIBM9BC1027206CB25437F276CCA8881B5018E12D01DE5EDA40580F9E8BF0D3E2205
HistoryMay 19, 2021 - 5:05 p.m.

Security Bulletin: A security vulnerability in Node.js netmask module affects IBM Cloud Pak for Multicloud Management Managed Service

2021-05-1917:05:04
www.ibm.com
13
node.js netmask
ibm cloud pak for multicloud management
ssrf
rfi
lfi
cvss
upgrade

EPSS

0.08

Percentile

94.4%

Summary

A security vulnerability in Node.js netmask module affects IBM Cloud Pak for Multicloud Management Managed Service.

Vulnerability Details

CVEID:CVE-2021-28918
**DESCRIPTION:**Node.js netmask module is vulnerable to server-side request forgery, caused by the improper handling of mixed-format IP addresses. By using a specially-crafted argument using octal literals, an attacker could exploit this vulnerability to conduct SSRF, RFI, and LFI attacks to gain access to intranets, VPNs, containers, adjacent VPC instances, or LAN hosts.
CVSS Base score: 9.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/198894 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3 by following the instructions in <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=installation-upgrade.&gt;

Workarounds and Mitigations

None

EPSS

0.08

Percentile

94.4%

Related for 9BC1027206CB25437F276CCA8881B5018E12D01DE5EDA40580F9E8BF0D3E2205