Lucene search

K
ibmIBMC15110971919E2CFDB4CF1D2D6CB0D06608CA8D7C1A8EBC251900CD5535890E1
HistoryMar 29, 2023 - 9:53 a.m.

Security Bulletin: IBM Event Streams is affected by a vulnerability in Golang Go (CVE-2022-41717)

2023-03-2909:53:12
www.ibm.com
13
ibm event streams
golang go
memory growth
denial of service
cve-2022-41717
upgrade
vulnerability
http/2
ibm cloud

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.003 Low

EPSS

Percentile

68.9%

Summary

This security vulnerability affects the memory growth in Go before version 1.18.9 that is used by IBM Event Streams.

Vulnerability Details

CVEID:CVE-2022-41717
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw when handling HTTP/2 requests in the Go server. By sending a specially-crafted keys, a remote attacker could exploit this vulnerability to cause excessive memory growth, and results in a denial of service condition.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/241875 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Event Streams 10.0.0, 10.1.0, 10.2.0-eus, 10.2.1-eus, 10.3.0, 10.3.1, 10.4.0, 10.5.0, 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, 11.1.0, 11.1.1, 11.1.2, 11.1.3, 11.1.4

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now by upgrading

Upgrade to IBM Event Streams 11.1.5 by following the upgrading and migrating documentation.

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmevent_streamsMatch10.0.0
OR
ibmevent_streamsMatch10.1.0
OR
ibmevent_streamsMatch10.2.0
OR
ibmevent_streamsMatch10.3.0
OR
ibmevent_streamsMatch10.3.1
OR
ibmevent_streamsMatch10.4.0
OR
ibmevent_streamsMatch10.5.0
OR
ibmevent_streamsMatch11.0.0
OR
ibmevent_streamsMatch11.0.1
OR
ibmevent_streamsMatch11.0.2
OR
ibmevent_streamsMatch10.2.0
OR
ibmevent_streamsMatch10.2.1

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.003 Low

EPSS

Percentile

68.9%