Security Bulletin: IBM Cloud Pak for Data is vulnerable to denial of service due to github.com/docker/distribution ( CVE-2023-2253 )
Discription

Summary Go module github.com/docker/distribution is used by IBM Cloud Pak for Data. CVE-2023-2253. Vulnerability Details ** CVEID: CVE-2023-2253 DESCRIPTION: **Distribution is vulnerable to a denial of service, caused by improper input validation by the /v2/_catalog endpoint. By sending a specially crafted /v2/_catalog API endpoint request request, a remote attacker could exploit this vulnerability to cause a denial of service condition. CVSS Base score: 7.5 CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/254846 for the current score. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Affected Products and Versions Affected Product(s)| Version(s) —|— IBM Cloud Pak for Data| 4.0.0-4.8.4 Remediation/Fixes IBM recommends addressing the vulnerability now. Product(s) | **Version(s) number and/or range ** | Remediation/Fix/Instructions —|—|— IBM Cloud Pak for Data | 4.0.0-4.8.4 | Download 4.8.5 and follow instructions Workarounds and Mitigations…Read More

Back to Main

Subscribe for the latest news: