Information disclosure in undici - CVE-2024-24758

 

Information disclosure in undici - CVE-2024-24758

Published: February 22, 2024 / Updated: February 22, 2024


Vulnerability identifier: #VU86709
CSH Severity: Low
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-24758
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the application does not clear the Proxy-Authentication HTTP header when handling cross-origin redirects. A remote attacker can gain access to sensitive information.


Affected software

undici
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Server
SUSE Enterprise Storage
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
openSUSE Leap
QRadar Suite
Cloud Pak for Network Automation
IBM Cloud Pak for Watson AIOps
Node.js
Cloud Pak for Data
IBM App Connect Enterprise
App Connect Enterprise Certified Container
nodejs16-debugsource
nodejs16-docs
nodejs16-devel
nodejs16
nodejs16-debuginfo
npm16
corepack16
nodejs
nodejs18-debuginfo
npm18
nodejs18
nodejs18-devel
nodejs18-debugsource
nodejs18-docs
corepack18
nodejs20
nodejs20-docs
nodejs20-debuginfo
nodejs20-devel
npm20
corepack20
nodejs20-debugsource

How to mitigate CVE-2024-24758

Install updates from vendor's website.

undici - addressed in versions 5.28.3, 6.6.1
QRadar Suite - update to 1.10.21.0
Cloud Pak for Network Automation - update to 2.7.2
Node.js - addressed in versions 18.19.1, 20.11.1, 21.6.2
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Cloud Pak for Data - update to 4.8.5
IBM App Connect Enterprise - addressed in versions 11.0.0.25, 12.0.11.3
App Connect Enterprise Certified Container - update to 11.3.0
nodejs16-debugsource - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-docs - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-devel - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
npm16 - addressed in versions 16.20.2-8.39.1, 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
corepack16 - addressed in versions 16.20.2-150300.7.33.1, 16.20.2-150400.3.30.1
nodejs - update to 18.18.2-1
nodejs18-debuginfo - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
npm18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18 - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-devel - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-debugsource - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
nodejs18-docs - addressed in versions 18.19.1-8.18.1, 18.19.1-150400.9.18.2
corepack18 - update to 18.19.1-150400.9.18.2
nodejs20 - update to 20.11.1-1
nodejs20-docs - update to 20.11.1-150500.11.6.1
nodejs20 - update to 20.11.1-150500.11.6.1
nodejs20-debuginfo - update to 20.11.1-150500.11.6.1
nodejs20-devel - update to 20.11.1-150500.11.6.1
npm20 - update to 20.11.1-150500.11.6.1
corepack20 - update to 20.11.1-150500.11.6.1
nodejs20-debugsource - update to 20.11.1-150500.11.6.1

External References

Related Security Bulletins