CVE Vulnerabilities

CVE-2024-45336

Published: Jan 28, 2025 | Modified: Feb 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/acm-prometheus-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/kube-rbac-proxy-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/kube-state-metrics-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/memcached-exporter-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/node-exporter-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/observatorium-rhel9:v2.11.7-10*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/observatorium-rhel9-operator:v2.11.7-13*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/prometheus-alertmanager-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/prometheus-rhel9:v2.11.7-8*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-addon-rhel9:v2.11.7-16*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/thanos-receive-controller-rhel9:v2.11.7-7*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/thanos-rhel9:v2.11.7-9*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/lighthouse-agent-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/lighthouse-coredns-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/nettest-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/subctl-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-gateway-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-globalnet-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-operator-bundle:v0.18.5-4*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-rhel9-operator:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.11 for RHEL 9RedHatrhacm2/submariner-route-agent-rhel9:v0.18.5-3*
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9RedHatrhacm2/lighthouse-agent-rhel9:v0.19.3-3*
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9RedHatrhacm2/nettest-rhel9:v0.19.3-3*
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9RedHatrhacm2/subctl-rhel9:v0.19.3-3*
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9RedHatrhacm2/submariner-gateway-rhel9:v0.19.3-3*
Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9RedHatrhacm2/submariner-rhel9-operator:v0.19.3-3*
Red Hat Ceph Storage 7.1RedHatrhceph/grafana-rhel9:10.4.16-1*
Red Hat Ceph Storage 7.1RedHatrhceph/keepalived-rhel9:2.2.8-50*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-7-rhel9:7-522*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-haproxy-rhel9:2.4.22-52*
Red Hat Ceph Storage 7.1RedHatrhceph/rhceph-promtail-rhel9:v3.0.0-21*
Red Hat Ceph Storage 7.1RedHatrhceph/snmp-notifier-rhel9:1.2.1-100*
Red Hat Enterprise Linux 10RedHatdelve-0:1.24.1-1.el10_0*
Red Hat Enterprise Linux 10RedHatgolang-0:1.23.7-1.el10_0*
Red Hat Enterprise Linux 10RedHatyggdrasil-0:0.4.5-3.el10_0*
Red Hat Enterprise Linux 10RedHatrhc-1:0.3.2-1.el10_0*
Red Hat Enterprise Linux 8RedHatgo-toolset:rhel8-8100020250321121115.a3795dee*
Red Hat Enterprise Linux 9RedHatopentelemetry-collector-0:0.107.0-8.el9_5*
Red Hat Enterprise Linux 9RedHatdelve-0:1.24.1-2.el9_5*
Red Hat Enterprise Linux 9RedHatgolang-0:1.23.6-2.el9_5*
Red Hat Enterprise Linux 9RedHatrhc-1:0.2.6-3.el9_6*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatopentelemetry-collector-0:0.107.0-7.el9_4*
Red Hat OpenShift Service Mesh 2.5 for RHEL 8RedHatopenshift-service-mesh/kiali-rhel8:1.73.20-2*
RHOL-6.1-RHEL-9RedHatopenshift-logging/cluster-logging-operator-bundle:v6.1.4-10*
RHOL-6.1-RHEL-9RedHatopenshift-logging/cluster-logging-rhel9-operator:v6.1.4-5*
RHOL-6.1-RHEL-9RedHatopenshift-logging/eventrouter-rhel9:v0.4.0-356*
RHOL-6.1-RHEL-9RedHatopenshift-logging/log-file-metric-exporter-rhel9:v1.1.0-337*
RHOL-6.1-RHEL-9RedHatopenshift-logging/logging-loki-rhel9:v3.4.2-6*
RHOL-6.1-RHEL-9RedHatopenshift-logging/loki-operator-bundle:v6.1.4-13*
RHOL-6.1-RHEL-9RedHatopenshift-logging/loki-rhel9-operator:v6.1.4-7*
RHOL-6.1-RHEL-9RedHatopenshift-logging/lokistack-gateway-rhel9:v0.1.0-752*
RHOL-6.1-RHEL-9RedHatopenshift-logging/opa-openshift-rhel9:v0.1.0-369*
RHOL-6.1-RHEL-9RedHatopenshift-logging/vector-rhel9:v0.37.1-34*
Satellite Client 6 for RHEL 8RedHatyggdrasil-0:0.2.3-3.el8sat*
Satellite Client 6 for RHEL 9RedHatyggdrasil-0:0.2.3-3.el9sat*
Red Hat OpenShift distributed tracing 3.5.1RedHatrhosdt/opentelemetry-rhel8-operator:sha256:7e0320614f3be4e8bb1442d5890d2a6cebaf0a1038599d6afbf50daca91e1d65*
GolangUbuntutrusty*
Golang-1.10Ubuntubionic*
Golang-1.10Ubuntutrusty*
Golang-1.10Ubuntutrusty/esm*
Golang-1.10Ubuntuxenial*
Golang-1.13Ubuntubionic*
Golang-1.13Ubuntufocal*
Golang-1.13Ubuntuxenial*
Golang-1.14Ubuntufocal*
Golang-1.16Ubuntubionic*
Golang-1.16Ubuntufocal*
Golang-1.18Ubuntubionic*
Golang-1.18Ubuntufocal*
Golang-1.20Ubuntufocal*
Golang-1.21Ubuntufocal*
Golang-1.22Ubuntuesm-apps/jammy*
Golang-1.22Ubuntufocal*
Golang-1.22Ubuntujammy*
Golang-1.22Ubuntunoble*
Golang-1.22Ubuntuoracular*
Golang-1.22Ubuntuupstream*
Golang-1.23Ubuntuoracular*
Golang-1.23Ubuntuupstream*
Golang-1.24Ubuntuplucky*
Golang-1.6Ubuntutrusty*
Golang-1.6Ubuntuxenial*
Golang-1.8Ubuntubionic*
Golang-1.9Ubuntubionic*

References