Lucene search

K
ibmIBMB4446604BF22B0FADB4734760BE3702528C603D13210360C1E225FF12A499CF7
HistoryMay 19, 2021 - 5:06 p.m.

Security Bulletin: A security vulnerability in Node.js pug and pug-code-gen module affects IBM Cloud Pak for Multicloud Management Managed Service.

2021-05-1917:06:25
www.ibm.com
12
node.js
pug
pug-code-gen
ibm cloud pak
multicloud management
vulnerability
remote execution
input validation
code execution
cve-2021-21353
cvss
update
fix
upgrade

EPSS

0.041

Percentile

92.2%

Summary

A security vulnerability in Node.js pug and pug-code-gen module affects IBM Cloud Pak for Multicloud Management Managed Service.

Vulnerability Details

CVEID:CVE-2021-21353
**DESCRIPTION:**Node.js pug and pug-code-gen could allow a remote attacker to execute arbitrary code on the system, caused by improper input validation by the pretty option of the pug compiler. By sending a specially-crafted request using the the query parameters, an attacker could exploit this vulnerability to execute arbitrary code on the node.js backend.
CVSS Base score: 9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/197688 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Pak for Multicloud Management Infrastructure Management All

Remediation/Fixes

Upgrade to IBM Cloud Pak for Multicloud Management 2.3 by following the instructions in <https://www.ibm.com/docs/en/cloud-paks/cp-management/2.3.x?topic=installation-upgrade.&gt;

Workarounds and Mitigations

None

EPSS

0.041

Percentile

92.2%

Related for B4446604BF22B0FADB4734760BE3702528C603D13210360C1E225FF12A499CF7