Summary Lua is used by IBM Cloud Pak for Data as part of the web interface. (CVE-2024-33531) Vulnerability Details ** CVEID: CVE-2024-33531 DESCRIPTION: **lua-resty-jwt could allow a remote attacker to bypass security restrictions, caused by improper authentication validation. By sending a specially crafted JWT with an enc header with the value A256GCM, an attacker could exploit this vulnerability to . CVSS Base score: 9.8 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/289412 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM Cloud Pak for Data| 4.0.0-4.8.4 Remediation/Fixes IBM strongly recommends addressing the vulnerability now. Product(s)| Version(s) number and/or range | Remediation/Fix/Instructions —|—|— IBM Cloud Pak for Data| 4.0.0-4.8.4| Download 4.8.5 and follow instructions Workarounds and Mitigations…Read More
References
Back to Main