A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fastify-static | Fastify | * | 4.2.4 (excluding) |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-grafana-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-must-gather-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | acm-operator-bundle-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | application-ui-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | assisted-image-service-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cert-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-backup-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | clusterclaims-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-curator-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | clusterlifecycle-state-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | cluster-proxy-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | config-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | console-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | console-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | discovery-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | endpoint-monitoring-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-propagator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-spec-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-status-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | governance-policy-template-sync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grafana-dashboard-loader-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grc-ui-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | grc-ui-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | iam-policy-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-client-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | insights-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-addon-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | klusterlet-operator-bundle-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-rbac-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | kube-state-metrics-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | managedcluster-import-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | management-ingress-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | memcached-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | metrics-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicloud-integrations-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicloud-manager-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multiclusterhub-repo-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-observability-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-application-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-channel-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-deployable-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-placementrule-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-subscription-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | multicluster-operators-subscription-release-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | node-exporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | observatorium-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | openshift-hive-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | placement-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-alertmanager-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | prometheus-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | provider-credential-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rbac-query-proxy-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | redisgraph-tls-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | registration-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | registration-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rhacm-agent-service-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rhacm-assisted-installer-agent-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rhacm-assisted-installer-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | rhacm-assisted-installer-reporter-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-aggregator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-api-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-collector-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-operator-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | search-ui-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | submariner-addon-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | thanos-receive-controller-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | volsync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | volsync-mover-rclone-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | volsync-mover-restic-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | volsync-mover-rsync-container | * |
Red Hat Advanced Cluster Management for Kubernetes 2 | RedHat | work-container | * |