Incorrect authorization in cross-fetch - CVE-2022-1365

 

Incorrect authorization in cross-fetch - CVE-2022-1365

Published: August 3, 2022


Vulnerability identifier: #VU66071
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1365
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to exposure of sensitive information due to insecure following of redirects. A remote attacker can force the application to redirect to a malicious website and gain access to authorization cookie.



Affected software

cross-fetch
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
IBM Business Automation Manager Open Editions
Red Hat Advanced Cluster Management for Kubernetes

How to mitigate CVE-2022-1365

Install updates from vendor's website.

cross-fetch - update to 3.1.5
Migration Toolkit for Containers - update to 1.7.3
Cloud Pak for Security (CP4S) - update to 1.10.7.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.1
IBM Business Automation Manager Open Editions - update to 8.0.1
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.4

External References

Related Security Bulletins