CVE Vulnerabilities

CVE-2024-45336

Published: Jan 28, 2025 | Modified: Feb 21, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat go-toolset:rhel8-8100020250321121115.a3795dee *
Red Hat Enterprise Linux 9 RedHat opentelemetry-collector-0:0.107.0-8.el9_5 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat opentelemetry-collector-0:0.107.0-7.el9_4 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/cluster-logging-operator-bundle:v6.1.4-10 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/cluster-logging-rhel9-operator:v6.1.4-5 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/eventrouter-rhel9:v0.4.0-356 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/log-file-metric-exporter-rhel9:v1.1.0-337 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/logging-loki-rhel9:v3.4.2-6 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/loki-operator-bundle:v6.1.4-13 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/loki-rhel9-operator:v6.1.4-7 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/lokistack-gateway-rhel9:v0.1.0-752 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/opa-openshift-rhel9:v0.1.0-369 *
RHOL-6.1-RHEL-9 RedHat openshift-logging/vector-rhel9:v0.37.1-34 *
Red Hat OpenShift distributed tracing 3.5.1 RedHat registry.redhat.io/rhosdt/opentelemetry-rhel8-operator:sha256:7e0320614f3be4e8bb1442d5890d2a6cebaf0a1038599d6afbf50daca91e1d65 *
Golang Ubuntu trusty *
Golang-1.10 Ubuntu bionic *
Golang-1.10 Ubuntu trusty *
Golang-1.10 Ubuntu trusty/esm *
Golang-1.10 Ubuntu xenial *
Golang-1.13 Ubuntu bionic *
Golang-1.13 Ubuntu xenial *
Golang-1.16 Ubuntu bionic *
Golang-1.18 Ubuntu bionic *
Golang-1.22 Ubuntu upstream *
Golang-1.23 Ubuntu upstream *
Golang-1.6 Ubuntu trusty *
Golang-1.6 Ubuntu xenial *
Golang-1.8 Ubuntu bionic *
Golang-1.9 Ubuntu bionic *

References