Bug 2248979 (CVE-2023-45857)

Summary: CVE-2023-45857 axios: exposure of confidential data stored in cookies
Product: [Other] Security Response Reporter: Robb Gatica <rgatica>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED COMPLETED QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aarif, aazores, adudiak, aileenc, amasferr, aprice, bdettelb, caswilli, chazlett, cmiranda, davidn, dfreiber, dhalasz, dhanak, dkenigsb, dkuc, dsimansk, dymurray, eaguilar, ebaron, ecerquei, epacific, eric.wittmann, fdeutsch, fjansen, gmalinko, gparvin, hkataria, ibek, ibolton, janstey, jburrell, jcammara, jcantril, jchui, jhardy, jkang, jkoehler, jmatthew, jmitchel, jmontleo, jneedle, jobarker, jpallich, jrokos, jsamir, jshaughn, jsherril, jtanner, jwendell, kaycoth, kingland, kshier, ktsao, kverlaen, lbainbri, lhein, mabashia, matzew, michel, mkholjur, mkudlej, mnovotny, mpierce, mwringe, nboldt, njean, oezr, omaciel, orabin, oramraz, osapryki, owatkins, pahickey, pantinor, parichar, pcongius, pdelbell, periklis, pierdipi, pjindal, porcelli, psegedy, rcernich, rguimara, rhaigner, rhuss, rjohnson, rogbas, rtaniwa, sdawley, sfroberg, simaishi, sipoyare, skontopo, slucidi, smcdonal, smullick, sseago, stcannon, sthirugn, tasato, teagle, tfister, tjochec, tkral, twalsh, vkrizan, vkumar, vmugicag, yguenane, zsadeh
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: axios 1.6.0 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Axios that may expose a confidential session token. This issue can allow a remote attacker to bypass security measures and view sensitive data.
Story Points: ---
Clone Of: Environment:
Last Closed: 2024-03-27 08:57:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2266570, 2266571, 2266572, 2266575, 2266577, 2266568, 2266573, 2266574, 2266576, 2267101    
Bug Blocks: 2248978    

Description Robb Gatica 2023-11-09 23:49:56 UTC
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.

https://github.com/axios/axios/issues/6006
https://github.com/jeffbski/wait-on/pull/147

Comment 4 Avinash Hanwate 2024-02-28 11:29:52 UTC
Created ansible-collection-awx-awx tracking bugs for this issue:

Affects: epel-all [bug 2266571]
Affects: fedora-all [bug 2266572]


Created cachelib tracking bugs for this issue:

Affects: fedora-all [bug 2266573]


Created fbthrift tracking bugs for this issue:

Affects: fedora-all [bug 2266574]


Created grafana tracking bugs for this issue:

Affects: fedora-all [bug 2266575]


Created pgadmin4 tracking bugs for this issue:

Affects: fedora-all [bug 2266576]


Created rstudio tracking bugs for this issue:

Affects: fedora-all [bug 2266577]

Comment 5 Michel Lind 2024-02-28 16:56:27 UTC
Is there a way to opt out of these for some packages? I keep getting false positives on website files that are never shipped as part of the binary RPMs

see

https://src.fedoraproject.org/rpms/cachelib/blob/rawhide/f/cachelib.spec
https://src.fedoraproject.org/rpms/fbthrift/blob/rawhide/f/fbthrift.spec

Comment 7 errata-xmlrpc 2024-04-02 19:30:00 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.4 for RHEL 9
  Red Hat Ansible Automation Platform 2.4 for RHEL 8

Via RHSA-2024:1640 https://access.redhat.com/errata/RHSA-2024:1640

Comment 8 errata-xmlrpc 2024-04-18 12:41:05 UTC
This issue has been addressed in the following products:

  Red Hat Migration Toolkit for Containers 1.8

Via RHSA-2024:1925 https://access.redhat.com/errata/RHSA-2024:1925