Red Hat released security updates for multiple products to remediate CVE-2024-28849 in the Node.js follow-redirects package. The flaw allows the Proxy-Authorization header to persist during a cross-domain redirect even when Authorization is removed, potentially exposing proxy-authentication credentials to the redirected destination. The issue is fixed in follow-redirects version 1.15.6; Red Hat states that upgrading is the only mitigation.
Affected advisories include Migration Toolkit for Applications 7.0.3 container images (RHSA-2024:3316), Network Observability 1.6.0 for Red Hat OpenShift (RHSA-2024:3868), and Red Hat Ansible Automation Platform 2.4 (RHSA-2024:3781). The updates also address additional bundled-component vulnerabilities, including denial-of-service, file-disclosure, certificate-validation, request-smuggling, and arbitrary-code-execution issues; organizations should apply the relevant updates across supported RHEL and OpenShift deployments.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2024:3989 for Migration Toolkit for Applications 6.2.3 container images. The update remediated CVE-2024-28849 and vulnerabilities affecting Keycloak, webpack-dev-middleware, axios, css-tools, Vert.x, Apache Commons components, and Jetty.
Red Hat issued Important-rated RHSA-2024:3868 for Network Observability 1.6.0 for OpenShift on RHEL 9. It addressed CVE-2024-28849 along with vulnerabilities in Go, golang-protobuf, webpack-dev-middleware, nodejs-ip, and Express.
Red Hat issued Important-rated RHSA-2024:3550 for HawtIO 4.0.0 in Red Hat Build of Apache Camel 4 for x86_64. The update remediated CVE-2024-28849 and flaws in Spring Security, nodejs-ip, jose4j, and netty-codec-http.
Red Hat issued Important-rated RHSA-2024:3316 for Migration Toolkit for Applications 7.0.3 container images, including fixes for CVE-2024-28849 and multiple Go, axios, css-tools, webpack-dev-middleware, and golang-protobuf vulnerabilities.
Red Hat issued Moderate-rated RHSA-2024:1474 for Logging for Red Hat OpenShift 5.8 on RHEL 9. The update remediated CVE-2024-28849 in follow-redirects and CVE-2024-24786, an infinite-loop denial-of-service flaw in golang-protobuf protojson.Unmarshal.
Patrick Del Bello reported CVE-2023-26364, an improper input-validation flaw in css-tools 4.3.0 and earlier. Crafted CSS can trigger regular-expression processing that causes a minor denial of service during CSS parsing; css-tools 4.3.1 fixes the issue.
The follow-redirects project fixed CVE-2024-28849 in version 1.15.6. Vulnerable versions retained the Proxy-Authorization header during cross-domain redirects, potentially disclosing proxy-authentication credentials to the redirected destination; no workaround besides upgrading was identified.
Red Hat released Moderate-rated RHSA-2024:3781 for Ansible Automation Platform 2.4 on RHEL 8 and 9. The update remediated 20 CVEs, including the follow-redirects credential-leak flaw CVE-2024-28849, and updated automation-controller, Automation Hub, ansible-core, and Receptor components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.