The vendor explicitly identifies these products as affected by this CVE.
- rh-dotnet31-aspnetcore-runtime-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-aspnetcore-targeting-pack-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-apphost-pack-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-host as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-hostfxr-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-runtime-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-sdk-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-sdk-3.1-source-built-artifacts as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-targeting-pack-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet-templates-3.1 as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- rh-dotnet31-dotnet.src as a component of .NET Core 3.1 on Red Hat Enterprise Linux
- Summary
- A flaw was found in node-fetch. When following a redirect to a third-party domain, node-fetch was forwarding sensitive headers such as "Authorization," "WWW-Authenticate," and "Cookie" to potentially untrusted targets. This flaw leads to the exposure of sensitive information to an unauthorized actor.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
