Lucene search

K
ibmIBMF3419AA7A116D5435DE30485E9B9DBD937F2CCB31C33548C7F0003177C1B45A7
HistoryAug 08, 2024 - 2:49 p.m.

Security Bulletin: IBM Cloud Pak for Data is vulnerable to arbitrary code execution during compilation due to traverse ( CVE-2023-45133 )

2024-08-0814:49:21
www.ibm.com
6
ibm cloud pak for data
arbitrary code execution
babel
vulnerability
compilation

CVSS3

9.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

Summary

Package traverse is used by IBM Cloud Pak for Data. CVE-2023-45133.

Vulnerability Details

CVEID:CVE-2023-45133
**DESCRIPTION:**Babel could allow a local attacker to execute arbitrary code on the system, caused by a flaw in the path.evaluate()or path.evaluateTruthy(). By using a specially crafted code to compile, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVSS Base score: 8.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/268647 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s)|**Version(s)
**
โ€”|โ€”
IBM Cloud Pak for Data| 4.0.0-4.8.4

Remediation/Fixes

IBM strongly recommends addressing the vulnerability now.

Product(s)

|

Version(s) number and/or range

|

Remediation/Fix/Instructions

โ€”|โ€”|โ€”

IBM Cloud Pak for Data

|

4.0.0-4.8.4

|

Download 4.8.5 and follow instructions

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmcloud_pak_for_dataMatch4.8.5
VendorProductVersionCPE
ibmcloud_pak_for_data4.8.5cpe:2.3:a:ibm:cloud_pak_for_data:4.8.5:*:*:*:*:*:*:*

CVSS3

9.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

Related for F3419AA7A116D5435DE30485E9B9DBD937F2CCB31C33548C7F0003177C1B45A7