The vendor explicitly identifies these products as affected by this CVE.
- cryostat-openshift-console-plugin-npm as a component of Cryostat 4
- grafana-infinity-datasource-npm as a component of Cryostat 4
- undici as a component of Cryostat 4
- openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines
- undici as a component of Red Hat AMQ Broker 7
- rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- nodejs as a component of Red Hat Enterprise Linux 8
- nodejs-devel as a component of Red Hat Enterprise Linux 8
- nodejs-docs as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in undici. An attacker-controlled upstream server can exploit a vulnerability in Undici's HTTP/1.1 client, specifically related to response queue poisoning on reused keep-alive sockets. This allows the attacker to inject an unsolicited HTTP/1.1 response onto an idle socket. Consequently, when the client dispatches a new request on that socket, it may associate the injected response with the new request, leading to responses being delivered to unintended recipients or requests. This could result in a low impact on data integrity.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
