IBM SDK for Node.js in IBM Bluemix are affected by a HTTP bearer token leak in the npm package management tool and two denial of service vulnerabilities in modules used by the npm package management tool.
CVE(s): CVE-2016-3956, CVE-2016-2515, CVE-2016-2537
Affected product(s) and affected version(s):
These vulnerabilities affect all versions up to and including IBM SDK for Node.js v1.1.0.20 and v1.2.0.10 and v4.4.1.0 corresponding to open-source version v0.10.42, v0.12.12 and v4.4.1, respectively.
To check which version of the Node.js runtime runtime your Bluemix application is using, navigate to the "Files" menu item for your application through the Bluemix UI. In the "logs" directory, check the "staging_task.log".
You can also find this file through the command-line Cloud Foundry client by running the following command:
cf files <appname> logs/staging_task.log
Look for the following lines:
-----> IBM SDK for Node.js Buildpack _______
If the Node.js engine version is not v0.10.44, v0.12.13 or v4.4.2, your application may be vulnerable.
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/21E2v9R
X-Force Database: http://ift.tt/1NSj7rJ
X-Force Database: http://ift.tt/1NSj7rH
X-Force Database: http://ift.tt/1rhWrqL
from IBM Product Security Incident Response Team http://ift.tt/21E2suJ
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.