Lucene search

K
ibmIBMCA3FEF2862FD126BC9D4EBDB2A09FB4119BD176D3192C86ECFE7F74F3338C1D9
HistoryJun 23, 2021 - 1:19 p.m.

Security Bulletin: IBM Cloud Transformation Advisor is affected by Node.js vulnerability

2021-06-2313:19:18
www.ibm.com
9

0.002 Low

EPSS

Percentile

59.0%

Summary

IBM Cloud Transformation Advisor has addressed Node.js vulnerability CVE-2021-31597

Vulnerability Details

CVEID:CVE-2021-31597
**DESCRIPTION:**Node.js xmlhttprequest-ssl module is vulnerable to a man-in-the-middle attack, caused by the disalbe of SSL certificate validation by default. An attacker could exploit this vulnerability to launch a man-in-the-middle attack and gain access to the communication channel between endpoints to obtain sensitive information or further compromise the system.
CVSS Base score: 6.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/200623 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Transformation Advisor 2.4.2, 2.4.3

Remediation/Fixes

Upgrade to 2.4.4 or later.

IBM Cloud Transformation Advisor can be installed from OperatorHub page in Red Hat OpenShift Container Platform or locally following this link.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud transformation advisoreq2.0

0.002 Low

EPSS

Percentile

59.0%

Related for CA3FEF2862FD126BC9D4EBDB2A09FB4119BD176D3192C86ECFE7F74F3338C1D9