Information disclosure in undici - CVE-2024-30260

 

Information disclosure in undici - CVE-2024-30260

Published: April 5, 2024


Vulnerability identifier: #VU88177
CSH Severity: Low
CVSS v4 BT: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-30260
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the application clears Authorization and Proxy-Authorization headers during cross-origin redirects for the fetch() method, however does not clear them for the undici.request() method, which can leak sensitive information to an unauthorized party.


Affected software

undici
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP4 LTSS
openSUSE Leap
openEuler
Red Hat OpenShift Dev Spaces
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Watson AIOps
Cloud Pak for Data
npm
v8-devel
nodejs16-devel
nodejs16-docs
nodejs16-debuginfo
nodejs16-debugsource
nodejs16
npm16
corepack16
nodejs18-debuginfo
nodejs18-docs
nodejs18
npm18
nodejs18-debugsource
nodejs18-devel
corepack18
nodejs-debuginfo
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs-debugsource
nodejs
nodejs20-debugsource
nodejs20
nodejs20-docs
npm20
nodejs20-devel
corepack20
nodejs20-debuginfo

How to mitigate CVE-2024-30260

Install updates from vendor's website.

undici - addressed in versions 5.28.4, 6.11.1
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Cloud Pak for Data - update to 4.8.5
IBM Decision Optimization for Cloud Pak for Data - update to 5.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.0.1
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
npm - update to 10.5.0-1.20.12.1.1
v8-devel - update to 11.3.244.8-1.20.12.1.1
nodejs16-devel - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-docs - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-debugsource - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16 - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
npm16 - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
corepack16 - update to 16.20.2-150400.3.36.1
nodejs18-debuginfo - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-docs - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18 - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
npm18 - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debugsource - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-devel - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
corepack18 - update to 18.20.1-150400.9.21.3
nodejs-debuginfo - update to 20.12.1-1
nodejs-docs - update to 20.12.1-1
nodejs-libs - update to 20.12.1-1
nodejs-full-i18n - update to 20.12.1-1
nodejs-devel - update to 20.12.1-1
nodejs-debugsource - update to 20.12.1-1
nodejs - update to 20.12.1-1
nodejs20-debugsource - update to 20.12.1-150500.11.9.2
nodejs20 - update to 20.12.1-150500.11.9.2
nodejs20-docs - update to 20.12.1-150500.11.9.2
npm20 - update to 20.12.1-150500.11.9.2
nodejs20-devel - update to 20.12.1-150500.11.9.2
corepack20 - update to 20.12.1-150500.11.9.2
nodejs20-debuginfo - update to 20.12.1-150500.11.9.2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins