Lucene search

K
ibmIBMCAB2E721824F0D862EF8F8E283F283FA3A82438C3D84276C60869762440E680C
HistoryJul 14, 2021 - 10:56 p.m.

Security Bulletin: IBM App Connect Enterprise Certified Container Operator may be vulnerable to DoS caused by a flaw in Golang module net/http (CVE-2021-31525)

2021-07-1422:56:15
www.ibm.com
9
ibm
app connect enterprise
certified container
operator
dos
golang
net/http
cve-2021-31525
vulnerability
remediation
upgrade

EPSS

0.009

Percentile

82.3%

Summary

The validation webhook in the Operator for IBM App Connect may be vulnerable to a denial of service vulnerability. By sending a message with a specially crafted header, an attacker could cause a denial of service condition in the validation webhook that prevents new deployments from completing or configuration changes to existing deployments to complete.

Vulnerability Details

CVEID:CVE-2021-31525
**DESCRIPTION:**Golang Go is vulnerable to a denial of service, caused by a flaw in net/http. By sending a specially-crafted header to ReadRequest or ReadResponse. Server, Transport, and Client, a remote attacker could exploit this vulnerability to cause a (panic) denial of service condition.
CVSS Base score: 7.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/202709 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
App Connect Enterprise Certified Container 1.0 with Operator
App Connect Enterprise Certified Container 1.1 with Operator
App Connect Enterprise Certified Container 1.2 with Operator
App Connect Enterprise Certified Container 1.3 with Operator
App Connect Enterprise Certified Container 1.4 with Operator

Remediation/Fixes

App Connect Enterprise Certified Container 1.0, 1.2, 1.3 and 1.4 CD

Upgrade to App Connect Enterprise Certified Container Operator version 1.5.0 (available in CASE 1.5.0) or higher.

App Connect Enterprise Certified Container 1.1 LTS

Upgrade to App Connect Enterprise Certified Container Operator version 1.1.2 EUS (available in CASE 1.1.2) or higher.

Workarounds and Mitigations

None