Information disclosure in undici - CVE-2024-24758
Published: February 22, 2024 / Updated: February 22, 2024
Vulnerability identifier: #VU86709
CSH Severity: Low
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-24758
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application does not clear the Proxy-Authentication HTTP header when handling cross-origin redirects. A remote attacker can gain access to sensitive information.
Affected software
undici
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Enterprise Storage
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
openSUSE Leap
QRadar Suite
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Node.js
Cloud Pak for Data
IBM App Connect Enterprise
App Connect Enterprise Certified Container
nodejs16-debugsource
nodejs16-docs
nodejs16-devel
nodejs16
nodejs16-debuginfo
npm16
corepack16
nodejs
nodejs18-debuginfo
npm18
nodejs18
nodejs18-devel
nodejs18-debugsource
nodejs18-docs
corepack18
nodejs20
nodejs20-docs
nodejs20-debuginfo
nodejs20-devel
npm20
corepack20
nodejs20-debugsource
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Enterprise Storage
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
openSUSE Leap
QRadar Suite
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Node.js
Cloud Pak for Data
IBM App Connect Enterprise
App Connect Enterprise Certified Container
nodejs16-debugsource
nodejs16-docs
nodejs16-devel
nodejs16
nodejs16-debuginfo
npm16
corepack16
nodejs
nodejs18-debuginfo
npm18
nodejs18
nodejs18-devel
nodejs18-debugsource
nodejs18-docs
corepack18
nodejs20
nodejs20-docs
nodejs20-debuginfo
nodejs20-devel
npm20
corepack20
nodejs20-debugsource
How to mitigate CVE-2024-24758
Install updates from vendor's website.
undici - addressed in versions 5.28.3, 6.6.1
QRadar Suite - update to 1.10.21.0
Cloud Pak for Network Automation - update to 2.7.2
Node.js - addressed in versions 18.19.1, 20.11.1, 21.6.2
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Cloud Pak for Data - update to 4.8.5
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.3
App Connect Enterprise Certified Container - update to 11.3.0
nodejs16-debugsource - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-docs - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-devel - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
npm16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
corepack16 - addressed in versions 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs - update to 18.18.2-1
nodejs18-debuginfo - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
npm18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-devel - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-debugsource - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-docs - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
corepack18 - update to 18.19.1-150400.9.18.2
nodejs20 - update to 20.11.1-1
nodejs20-docs - update to 20.11.1-150500.11.6.1
nodejs20 - update to 20.11.1-150500.11.6.1
nodejs20-debuginfo - update to 20.11.1-150500.11.6.1
nodejs20-devel - update to 20.11.1-150500.11.6.1
npm20 - update to 20.11.1-150500.11.6.1
corepack20 - update to 20.11.1-150500.11.6.1
nodejs20-debugsource - update to 20.11.1-150500.11.6.1
QRadar Suite - update to 1.10.21.0
Cloud Pak for Network Automation - update to 2.7.2
Node.js - addressed in versions 18.19.1, 20.11.1, 21.6.2
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Cloud Pak for Data - update to 4.8.5
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.3
App Connect Enterprise Certified Container - update to 11.3.0
nodejs16-debugsource - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-docs - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-devel - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
npm16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
corepack16 - addressed in versions 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs - update to 18.18.2-1
nodejs18-debuginfo - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
npm18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-devel - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-debugsource - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-docs - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
corepack18 - update to 18.19.1-150400.9.18.2
nodejs20 - update to 20.11.1-1
nodejs20-docs - update to 20.11.1-150500.11.6.1
nodejs20 - update to 20.11.1-150500.11.6.1
nodejs20-debuginfo - update to 20.11.1-150500.11.6.1
nodejs20-devel - update to 20.11.1-150500.11.6.1
npm20 - update to 20.11.1-150500.11.6.1
corepack20 - update to 20.11.1-150500.11.6.1
nodejs20-debugsource - update to 20.11.1-150500.11.6.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Undici for Node.js
- Multiple vulnerabilities in Node.js
- SUSE update for nodejs18
- SUSE update for nodejs20
- SUSE update for nodejs16
- SUSE update for nodejs18
- SUSE update for nodejs16
- SUSE update for nodejs16
- Information disclosure in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in IBM App Connect Enterprise
- Multiple vulnerabilities in IBM Cloud Pak for Network Automation
- Amazon Linux AMI update for nodejs
- Amazon Linux AMI update for nodejs20
- Information disclosure in IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Cloud Pak for AIOps