The vendor explicitly identifies these products as affected by this CVE.
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- rhoai/odh-automl-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-kserve-autogluon-server-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-kserve-storage-initializer-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in httpcore2, a component used by HTTPX2. When a remote origin uses WebSocket Secure (wss) through a SOCKS5 proxy, httpcore2 fails to initiate Transport Layer Security (TLS) encryption because its upgrade condition only recognizes HTTPS. This vulnerability allows an attacker controlling or observing the proxy path to intercept and read sensitive WebSocket traffic, including authentication details and data frames, as it is transmitted in plaintext. The attacker could also modify the traffic or impersonate the WebSocket server, leading to information disclosure and potential compromise of communication integrity.
- Remediation
- Affected
