Summary: | CVE-2022-45411 Mozilla: Cross-Site Tracing was possible via non-standard override headers | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | erack, jhorak, nobody, stransky, tpopela |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | thunderbird 102.5, firefox 102.5 | Doc Type: | If docs needed, set a value |
Doc Text: |
The Mozilla Foundation Security Advisory describes this flaw as: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-standard headers such as X-Http-Method-Override that override the HTTP method, and made this attack possible again. Firefox has applied the same mitigations to the use of this and similar headers.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2022-12-14 19:18:32 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Bug Depends On: | 2141544, 2141545, 2141546, 2141547, 2141548, 2141549, 2141550, 2141551, 2141552, 2141553, 2141554, 2141556, 2141559, 2141560, 2141561, 2141562, 2141563, 2141564, 2141565, 2141566, 2141567, 2141569, 2141570, 2141571 | ||
Bug Blocks: | 2141542 |
Description
Dhananjay Arunesh
2022-11-16 10:56:32 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2022:8543 https://access.redhat.com/errata/RHSA-2022:8543 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Extended Update Support Via RHSA-2022:8544 https://access.redhat.com/errata/RHSA-2022:8544 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2022:8545 https://access.redhat.com/errata/RHSA-2022:8545 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:8547 https://access.redhat.com/errata/RHSA-2022:8547 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2022:8548 https://access.redhat.com/errata/RHSA-2022:8548 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Telecommunications Update Service Via RHSA-2022:8550 https://access.redhat.com/errata/RHSA-2022:8550 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Extended Update Support Via RHSA-2022:8549 https://access.redhat.com/errata/RHSA-2022:8549 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Via RHSA-2022:8553 https://access.redhat.com/errata/RHSA-2022:8553 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2022:8552 https://access.redhat.com/errata/RHSA-2022:8552 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:8554 https://access.redhat.com/errata/RHSA-2022:8554 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions Via RHSA-2022:8556 https://access.redhat.com/errata/RHSA-2022:8556 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2022:8555 https://access.redhat.com/errata/RHSA-2022:8555 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:8561 https://access.redhat.com/errata/RHSA-2022:8561 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:8580 https://access.redhat.com/errata/RHSA-2022:8580 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2022:8979 https://access.redhat.com/errata/RHSA-2022:8979 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2022:8980 https://access.redhat.com/errata/RHSA-2022:8980 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-45411 |