An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information. https://github.com/axios/axios/issues/6006 https://github.com/jeffbski/wait-on/pull/147
Created ansible-collection-awx-awx tracking bugs for this issue: Affects: epel-all [bug 2266571] Affects: fedora-all [bug 2266572] Created cachelib tracking bugs for this issue: Affects: fedora-all [bug 2266573] Created fbthrift tracking bugs for this issue: Affects: fedora-all [bug 2266574] Created grafana tracking bugs for this issue: Affects: fedora-all [bug 2266575] Created pgadmin4 tracking bugs for this issue: Affects: fedora-all [bug 2266576] Created rstudio tracking bugs for this issue: Affects: fedora-all [bug 2266577]
Is there a way to opt out of these for some packages? I keep getting false positives on website files that are never shipped as part of the binary RPMs see https://src.fedoraproject.org/rpms/cachelib/blob/rawhide/f/cachelib.spec https://src.fedoraproject.org/rpms/fbthrift/blob/rawhide/f/fbthrift.spec
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:1640 https://access.redhat.com/errata/RHSA-2024:1640
This issue has been addressed in the following products: Red Hat Migration Toolkit for Containers 1.8 Via RHSA-2024:1925 https://access.redhat.com/errata/RHSA-2024:1925
This issue has been addressed in the following products: RHEL-9-CNV-4.15 Via RHSA-2024:3314 https://access.redhat.com/errata/RHSA-2024:3314
This issue has been addressed in the following products: MTA-7.0-RHEL-9 MTA-7.0-RHEL-8 Via RHSA-2024:3316 https://access.redhat.com/errata/RHSA-2024:3316
This issue has been addressed in the following products: RHEL-9-CNV-4.14 Via RHSA-2024:3473 https://access.redhat.com/errata/RHSA-2024:3473
This issue has been addressed in the following products: MTA-6.2-RHEL-9 MTA-6.2-RHEL-8 Via RHSA-2024:3989 https://access.redhat.com/errata/RHSA-2024:3989
This issue has been addressed in the following products: RHEL-8-CNV-4.12 Via RHSA-2024:4269 https://access.redhat.com/errata/RHSA-2024:4269
This issue has been addressed in the following products: RHEL-9-CNV-4.16 Via RHSA-2024:4455 https://access.redhat.com/errata/RHSA-2024:4455
This issue has been addressed in the following products: RHEL-9-CNV-4.13 Via RHSA-2024:5314 https://access.redhat.com/errata/RHSA-2024:5314
This issue has been addressed in the following products: Red Hat Advanced Cluster Security 4.7 Via RHSA-2025:2876 https://access.redhat.com/errata/RHSA-2025:2876