Information disclosure in undici - CVE-2023-45143

 

Information disclosure in undici - CVE-2023-45143

Published: October 17, 2023 / Updated: October 18, 2023


Vulnerability identifier: #VU82066
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-45143
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to software send Cookies in HTTP headers during cross-origin redirects. A remote attacker can gain unauthorized access to sensitive information.


Affected software

undici
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Fedora
EasyApache
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Spectrum Control
IBM Cloud Pak for Business Automation
IBM Business Automation Workflow
IBM Cloud Pak for Watson AIOps
Cloud Pak for Network Automation
Storage Ceph
IBM App Connect Enterprise
Node.js
IBM Security QRadar Analyst Workflow
nodejs-nodemon
npm
nodejs16-docs
nodejs16-debuginfo
nodejs16-devel
nodejs16-debugsource
nodejs16
npm16
corepack16
nodejs
nodejs18
nodejs-full-i18n
nodejs-devel
nodejs-docs
nodejs18-devel
nodejs18-docs
nodejs18-debugsource
npm18
nodejs18-debuginfo
nodejs20
net-libs/nodejs
nodejs-packaging
nodejs-packaging-bundler
Cloud Pak for Data

How to mitigate CVE-2023-45143

Install updates from vendor's website.

undici - update to 5.26.2
EasyApache - update to 4 2023-10-18
IBM App Connect Enterprise - update to 12.0.10.1
Node.js - addressed in versions 18.18.2, 20.8.1
Cloud Pak for Network Automation - update to 2.7
IBM Security QRadar Analyst Workflow - update to 2.33.1
nodejs-nodemon - update to 3.0.1-1
IBM Decision Optimization for Cloud Pak for Data - update to 4.8.3
Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0
App Connect Enterprise Certified Container - addressed in versions 5.0.14, 11.2.0
IBM Spectrum Control - update to 5.4.11
Storage Ceph - update to 6.1z3
npm - update to 9.8.1-1.18.18.2.1.0.1
nodejs16-docs - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
nodejs16-debuginfo - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
nodejs16-devel - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
nodejs16-debugsource - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
nodejs16 - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
npm16 - addressed in versions 16.20.2-8.36.1, 16.20.2-150300.7.30.1, 16.20.2-150400.3.27.2
corepack16 - update to 16.20.2-150300.7.30.1
nodejs - update to 18.18.2-1
nodejs18 - addressed in versions 18.18.2-1.fc37, 18.18.2-1.fc38, 18.18.2-1.fc39
nodejs-full-i18n - update to 18.18.2-1.0.1
nodejs-devel - update to 18.18.2-1.0.1
nodejs - update to 18.18.2-1.0.1
nodejs-docs - update to 18.18.2-1.0.1
nodejs18-devel - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
nodejs18-docs - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
nodejs18-debugsource - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
nodejs18 - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
npm18 - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
nodejs18-debuginfo - addressed in versions 18.18.2-8.15.1, 18.18.2-150400.9.15.1
nodejs20 - addressed in versions 20.8.1-1.fc37, 20.8.1-1.fc38, 20.8.1-1.fc39
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5
net-libs/nodejs - update to 22.4.1
IBM Business Automation Workflow - update to 23.0.2
nodejs-packaging - update to 2021.06-4
nodejs-packaging-bundler - update to 2021.06-4

External References

Related Security Bulletins