The vendor explicitly identifies these products as affected by this CVE.
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gaudi-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/disk-image-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhoai/odh-core-bff-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-dashboard-operator-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-dashboard-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-agent-ops-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-autorag-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-eval-hub-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-mod-arch-gen-ai-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in fastify. When configured with a numeric `trustProxy` value, an attacker who can directly access the Fastify origin, bypassing the front-facing proxy, can spoof forwarded request fields. This vulnerability allows for host injection in generated URLs, bypasses HTTPS enforcement, and can lead to secure-cookie and Cross-Site Request Forgery (CSRF) origin bypasses, as well as host-based routing and cache poisoning.
- Remediation
- Fix deferred
