VDB
BDU%3A2024-02610
BDU%3A2024-02610
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость модуля Node.js follow-redirects, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, Red Hat Inc., Fedora Project | SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, Debian GNU/Linux, Red Hat Advanced Cluster Management for Kubernetes, Red Hat Discovery, Fedora, follow-redirects, multicluster engine for Kubernetes, Red Hat OpenShift Logging (RHOL) |
Timeline
- Apr 4, 2024 CVE Published
References
- https://fetch.spec.whatwg.org/#authentication-entries url
- https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b url
- https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp url
- https://github.com/psf/requests/issues/1885 url
- https://www.suse.com/security/cve/CVE-2024-28849.html url
- https://security-tracker.debian.org/tracker/CVE-2024-28849 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOIF4EPQUCKDBEVTGRQDZ3CGTYQHPO7Z/ advisory
- https://access.redhat.com/security/cve/CVE-2024-28849 advisory