Lucene search

K
ibmIBMFF5A8A25C6F29CF39641217FCD026C317D3243C49B57A257E96A9297D83DE158
HistoryJun 22, 2021 - 3:56 p.m.

Security Bulletin: IBM Cloud Transformation Advisor is affected by Node.js vulnerability

2021-06-2215:56:46
www.ibm.com
17

0.006 Low

EPSS

Percentile

78.7%

Summary

IBM Cloud Transformation Advisor has addressed Node.js vulnerability CVE-2021-23337

Vulnerability Details

CVEID:CVE-2021-23337
**DESCRIPTION:**Node.js lodash module could allow a remote authenticated attacker to execute arbitrary commands on the system, caused by a command injection flaw in the template. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system.
CVSS Base score: 7.2
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/196797 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Cloud Transformation Advisor 2.4.2, 2.4.3

Remediation/Fixes

Upgrade to 2.4.4 or later.

IBM Cloud Transformation Advisor can be installed from OperatorHub page in Red Hat OpenShift Container Platform or locally following this link.

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm cloud transformation advisoreq2.0

0.006 Low

EPSS

Percentile

78.7%

Related for FF5A8A25C6F29CF39641217FCD026C317D3243C49B57A257E96A9297D83DE158