CVE-2024-39008: Critical severity ibm cloud pak for security vulnerability
robinweser fast-loops could allow a remote attacker to execute arbitrary code on the system, caused by a prototype pollution in the function objectMergeDeep. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service.
Other sources
robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
— GitHub
robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39008?
CVE-2024-39008 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-39008?
To mitigate CVE-2024-39008, update the 'fast-loops' package to version 1.1.4 or later.
Which software is affected by CVE-2024-39008?
CVE-2024-39008 affects the 'fast-loops' package, IBM Cloud Pak for Security versions up to 1.10.0.0 - 1.10.11.0, and IBM QRadar Suite Software versions up to 1.10.12.0 - 1.10.23.0.
What type of attack is possible with CVE-2024-39008?
CVE-2024-39008 allows a remote attacker to execute arbitrary code or cause a denial of service on the affected systems.
What component is vulnerable in CVE-2024-39008?
The vulnerability in CVE-2024-39008 originates from a prototype pollution issue in the 'objectMergeDeep' function.