Security Bulletin:  IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is affected by a Denial of Service Vulnerability in Nimbus-JOSE-JWT (CVE-2023-52428)
Discription

Summary Connect2id Nimbus-JOSE-JWT is used by IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) as part of the openid authentication options. Connect2id Nimbus-JOSE-JWT is vulnerable to a denial of service, caused by improper validation of user requests by the PasswordBasedDecrypter (PBKDF2) component. By sending a specially crafted request using a large JWE p2c header, a remote attacker could exploit this vulnerability to cause a denial of service. Vulnerability Details ** CVEID: CVE-2023-52428 DESCRIPTION: **Connect2id Nimbus-JOSE-JWT is vulnerable to a denial of service, caused by improper validation of user requests by the PasswordBasedDecrypter (PBKDF2) component. By sending a specially crafted request using a large JWE p2c header, a remote attacker could exploit this vulnerability to cause a denial of service. CVSS Base score: 7.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/284044 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— UCD – IBM UrbanCode Deploy| 7.1 – 7.1.2.17 UCD – IBM UrbanCode Deploy| 7.2 – 7.2.3.10 UCD – IBM UrbanCode Deploy| 7.3 – 7.3.2.5 UCD – IBM DevOps Deploy| 8.0 – 8.0.1.0 Remediation/Fixes IBM strongly suggests the following: Upgrade affected versions to any of 7.1.2.18, 7.2.3.11, 7.3.2.6, or 8.0.1.1 or later Workarounds and Mitigations…Read More

Back to Main

Subscribe for the latest news: