CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
描述
Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Cookie` headers. By design, `cookie` headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since undici handles headers more liberally than the spec, there was a disconnect from the assumptions the spec made, and undici's implementation of fetch. As such this may lead to accidental leakage of cookie to a third-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the third party site. This was patched in version 5.26.2. There are no known workarounds.
如何修補 CVE-2023-45143
要修補 CVE-2023-45143,請將受影響套件升級到下列已修補版本。
- —升級至 18.18.2-r0 或更新版本
- —升級至 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u2 或更新版本
- —升級至 5.26.2 或更新版本
CVE-2023-45143 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 18.18.2-r0
- from 0, < 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u2
- from 0, < 5.26.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.9 | CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L |