Preload arbitrary resources by injecting additional `Link` headers
Published Oct 29, 2024
5.4
MEDIUMCVSS 3.1
EPSS 0.44%
Description
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.
The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources.
This vulnerability is especially relevant for dynamic parameters.
Affected products
-
- Version 3.0.0-alpha1StatusaffectedConstraints<=3.21.2
- Version
-
- Version 3.0.0-alpha1StatusaffectedConstraints<=3.21.2
- Version
A-MQ Interconnect 1
qpid-dispatch
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/logging-view-plugin-rhel8
Not affected
Migration Toolkit for Applications 7
mta/mta-cli-rhel9
Not affected
Migration Toolkit for Applications 7
mta/mta-ui-rhel9
Not affected
Migration Toolkit for Containers
rhmtc/openshift-migration-ui-rhel8
Not affected
Migration Toolkit for Virtualization
migration-toolkit-virtualization/mtv-console-plugin-rhel9
Not affected
Multicluster Engine for Kubernetes
multicluster-engine/console-mce-rhel8
Not affected
Network Observability Operator
network-observability/network-observability-console-plugin-rhel9
Not affected
Node HealthCheck Operator
workload-availability/node-remediation-console-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-api-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-db-migration-rhel8
Not affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-ossmc-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Not affected
Red Hat 3scale API Management Platform 2
3scale-amp-system-container
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/console-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-central-db-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-main-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-rhel8-operator
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-roxctl-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-scanner-v4-db-rhel8
Not affected
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-scanner-v4-rhel8
Not affected
Red Hat Ansible Automation Platform 2
aap-cloud-ui-container
Not affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Not affected
Red Hat Ansible Automation Platform 2
automation-controller
Not affected
Red Hat Ansible Automation Platform 2
automation-eda-controller
Not affected
Red Hat Ansible Automation Platform 2
automation-gateway
Not affected
Red Hat Connectivity Link 1
rhcl-console-plugin-container
Not affected
Red Hat Developer Hub
rhdh-operator-container
Not affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat Discovery 1
discovery-server-container
Not affected
Red Hat Enterprise Linux 10
cldr-emoji-annotation
Not affected
Red Hat Enterprise Linux 10
pcs
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
cldr-emoji-annotation
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
pcs
Not affected
Red Hat Enterprise Linux 9
cldr-emoji-annotation
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
pcs
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat OpenShift AI (RHOAI)
odh-dashboard-container
Not affected
Red Hat OpenShift AI (RHOAI)
odh-operator-container
Not affected
Red Hat OpenShift Container Platform 4
openshift4/nmstate-console-plugin-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-monitoring-plugin-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-networking-console-plugin-rhel9
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-dashboard-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-operator-rhel8
Not affected
Red Hat OpenShift Data Science (RHODS)
rhods/odh-rhel8-operator
Not affected
Red Hat OpenShift Dev Spaces
devspaces/traefik-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argocd-rhel9
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/console-plugin-rhel8
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin-rhel9
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-agent-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-all-in-one-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-collector-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-es-index-cleaner-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-es-rollover-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-ingester-rhel8
Not affected
Red Hat OpenShift distributed tracing 3
rhosdt/jaeger-query-rhel8
Not affected
Red Hat OpenStack Platform 17.1
qpid-dispatch
Not affected
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Not affected
Red Hat Openshift Data Foundation 4
odf4/ocs-client-console-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-console-rhel9
Not affected
Red Hat Openshift Data Foundation 4
odf4/odf-multicluster-console-rhel9
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Satellite 6
qpid-dispatch
Not affected
Red Hat Satellite 6
satellite-capsule:el8/qpid-dispatch
Not affected
Red Hat Satellite 6
satellite:el8/qpid-dispatch
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| A-MQ Interconnect 1 | qpid-dispatch | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-view-plugin-rhel8 | Not affected | n/a |
| Migration Toolkit for Applications 7 | mta/mta-cli-rhel9 | Not affected | n/a |
| Migration Toolkit for Applications 7 | mta/mta-ui-rhel9 | Not affected | n/a |
| Migration Toolkit for Containers | rhmtc/openshift-migration-ui-rhel8 | Not affected | n/a |
| Migration Toolkit for Virtualization | migration-toolkit-virtualization/mtv-console-plugin-rhel9 | Not affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/console-mce-rhel8 | Not affected | n/a |
| Network Observability Operator | network-observability/network-observability-console-plugin-rhel9 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-remediation-console-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-api-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-db-migration-rhel8 | Not affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-ossmc-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Not affected | n/a |
| Red Hat 3scale API Management Platform 2 | 3scale-amp-system-container | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/console-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-central-db-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-rhel8-operator | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-roxctl-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-db-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-scanner-v4-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | aap-cloud-ui-container | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-controller | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-eda-controller | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-gateway | Not affected | n/a |
| Red Hat Connectivity Link 1 | rhcl-console-plugin-container | Not affected | n/a |
| Red Hat Developer Hub | rhdh-operator-container | Not affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat Discovery 1 | discovery-server-container | Not affected | n/a |
| Red Hat Enterprise Linux 10 | cldr-emoji-annotation | Not affected | n/a |
| Red Hat Enterprise Linux 10 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cldr-emoji-annotation | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | cldr-emoji-annotation | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-dashboard-container | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | odh-operator-container | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/nmstate-console-plugin-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-monitoring-plugin-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-networking-console-plugin-rhel9 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-dashboard-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-operator-rhel8 | Not affected | n/a |
| Red Hat OpenShift Data Science (RHODS) | rhods/odh-rhel8-operator | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argocd-rhel9 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/console-plugin-rhel8 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin-rhel9 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-agent-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-all-in-one-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-collector-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-es-index-cleaner-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-es-rollover-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-ingester-rhel8 | Not affected | n/a |
| Red Hat OpenShift distributed tracing 3 | rhosdt/jaeger-query-rhel8 | Not affected | n/a |
| Red Hat OpenStack Platform 17.1 | qpid-dispatch | Not affected | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/ocs-client-console-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-console-rhel9 | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/odf-multicluster-console-rhel9 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Satellite 6 | qpid-dispatch | Not affected | n/a |
| Red Hat Satellite 6 | satellite-capsule:el8/qpid-dispatch | Not affected | n/a |
| Red Hat Satellite 6 | satellite:el8/qpid-dispatch | Not affected | n/a |
express
npm
Introduced 0 Fixed 4.0.0-rc1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | express | 0 | 4.0.0-rc1 |
Remediation
Red Hat statement
This CVE affects Express versions 3.21.4 and prior, which have reached end of life status. No Red Hat products are affected by this vulnerability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-10491 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2322502 Issue Tracking
- https://github.com/advisories/GHSA-cm5g-3pgc-8rg4 Advisory
- https://github.com/expressjs/express/issues/6222
- https://nvd.nist.gov/vuln/detail/CVE-2024-10491
- https://www.cve.org/CVERecord?id=CVE-2024-10491
- https://www.herodevs.com/vulnerability-directory/cve-2024-10491 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-10491 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2322502 | Issue Tracking | |
| https://github.com/advisories/GHSA-cm5g-3pgc-8rg4 | Advisory | |
| https://github.com/expressjs/express/issues/6222 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-10491 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-10491 | ||
| https://www.herodevs.com/vulnerability-directory/cve-2024-10491 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.