The vendor explicitly identifies these products as affected by this CVE.
- arrow.src as a component of Red Hat Ceph Storage 7
- pybind.src as a component of Red Hat Ceph Storage 7
- thrift as a component of Red Hat Ceph Storage 7
- thrift.src as a component of Red Hat Ceph Storage 7
- arrow.src as a component of Red Hat Ceph Storage 8
- perl-thrift as a component of Red Hat Ceph Storage 8
- python3-thrift as a component of Red Hat Ceph Storage 8
- thrift as a component of Red Hat Ceph Storage 8
- thrift-devel as a component of Red Hat Ceph Storage 8
- thrift-glib as a component of Red Hat Ceph Storage 8
- thrift-qt as a component of Red Hat Ceph Storage 8
- thrift.src as a component of Red Hat Ceph Storage 8
- Summary
- The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
- Remediation
- The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io using the "podman pull" command.
