Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Follow_redirects | Follow-redirects | * | 1.15.4 (excluding) |
Migration Toolkit for Virtualization 2.5 | RedHat | migration-toolkit-virtualization/mtv-console-plugin-rhel9:2.5.5-3 | * |
MTA-6.2-RHEL-8 | RedHat | mta/mta-rhel8-operator:6.2.2-3 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-hub-rhel9:6.2.2-2 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-operator-bundle:6.2.2-5 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-pathfinder-rhel9:6.2.2-2 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-ui-rhel9:6.2.2-2 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-windup-addon-rhel9:6.2.2-3 | * |
MTA-6.2-RHEL-9 | RedHat | mta/mta-ui-rhel9:6.2.3-2 | * |
MTA-7.0-RHEL-9 | RedHat | mta/mta-cli-rhel9:7.0.3-16 | * |
MTA-7.0-RHEL-9 | RedHat | mta/mta-ui-rhel9:7.0.3-13 | * |
MTR 1.2.4 | RedHat | follow-redirects | * |
Multicluster engine for Kubernetes 2.4 for RHEL 8 | RedHat | multicluster-engine/console-mce-rhel8:v2.4.5-25 | * |
Multicluster engine for Kubernetes 2.4 for RHEL 8 | RedHat | multicluster-engine/multicluster-engine-console-mce-rhel8:v2.4.5-25 | * |
NETWORK-OBSERVABILITY-1.5.0-RHEL-9 | RedHat | network-observability/network-observability-console-plugin-rhel9:v1.5.0-89 | * |
Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 | RedHat | rhacm2/console-rhel8:v2.9.4-22 | * |
Red Hat OpenShift Container Platform 4.15 | RedHat | openshift4/ose-monitoring-plugin-rhel8:v4.15.0-202402082307.p0.gc3d2272.assembly.stream.el8 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-agent-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-all-in-one-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-collector-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-es-index-cleaner-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-es-rollover-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-ingester-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-operator-bundle:1.53.0-15 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-query-rhel8:1.53.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/jaeger-rhel8-operator:1.53.0-3 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/opentelemetry-collector-rhel8:0.93.0-3 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/opentelemetry-operator-bundle:0.93.0-8 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/opentelemetry-rhel8-operator:0.93.0-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/opentelemetry-target-allocator-rhel8:0.93.0-3 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-gateway-opa-rhel8:1.0.0-1 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-gateway-rhel8:1.0.0-1 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-operator-bundle:0.8.0-8 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-query-rhel8:0.8.0-3 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-rhel8:2.3.1-2 | * |
Red Hat Openshift distributed tracing 3.1 | RedHat | rhosdt/tempo-rhel8-operator:0.8.0-2 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/grafana-rhel8:2.5.1-2 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/istio-cni-rhel8:2.5.1-8 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/istio-must-gather-rhel8:2.5.1-3 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/istio-rhel8-operator:2.5.1-7 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/kiali-ossmc-rhel8:1.73.7-2 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/kiali-rhel8:1.73.7-5 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/kiali-rhel8-operator:1.73.7-4 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/pilot-rhel8:2.5.1-8 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/proxyv2-rhel8:2.5.1-8 | * |
Red Hat OpenShift Service Mesh 2.5 for RHEL 8 | RedHat | openshift-service-mesh/ratelimit-rhel8:2.5.1-2 | * |
RHEL-9-CNV-4.15 | RedHat | container-native-virtualization/kubevirt-console-plugin-rhel9:v4.15.2-383 | * |
RHODF-4.15-RHEL-9 | RedHat | odf4/odf-console-rhel9:v4.15.0-57 | * |
RHODF-4.15-RHEL-9 | RedHat | odf4/odf-multicluster-console-rhel9:v4.15.0-54 | * |
RHOL-5.8-RHEL-9 | RedHat | openshift-logging/logging-view-plugin-rhel9:v5.8.2-3 | * |
Node-follow-redirects | Ubuntu | bionic | * |
Node-follow-redirects | Ubuntu | lunar | * |
Node-follow-redirects | Ubuntu | mantic | * |
Node-follow-redirects | Ubuntu | trusty | * |
Node-follow-redirects | Ubuntu | xenial | * |