The vendor explicitly identifies these products as affected by this CVE.
- cryostat-openshift-console-plugin-npm as a component of Cryostat 4
- grafana-infinity-datasource-npm as a component of Cryostat 4
- undici as a component of Cryostat 4
- openshift-pipelines/pipelines-console-plugin-pf5-rhel9 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel8 as a component of OpenShift Pipelines
- openshift-pipelines/pipelines-console-plugin-rhel9 as a component of OpenShift Pipelines
- undici as a component of Red Hat AMQ Broker 7
- rh-podman-desktop.git as a component of Red Hat Build of Podman Desktop
- rhdh/rhdh-hub-rhel9 as a component of Red Hat Developer Hub
- nodejs as a component of Red Hat Enterprise Linux 10
- nodejs-devel as a component of Red Hat Enterprise Linux 10
- nodejs-docs as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in undici. The cookie parser in the `parseSetCookie` function incorrectly decodes cookie values, which is contrary to standard specifications. This vulnerability allows an attacker-controlled upstream to inject arbitrary HTTP response headers, such as `Set-Cookie`, `Location`, or `Cache-Control`. The primary consequence is HTTP response header injection, which can lead to session fixation, open redirect, or cache poisoning.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
