CVE-2024-29041 Affecting kubeflow-centraldashboard package, versions <1.8.0-r3
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-WOLFILATEST-KUBEFLOWCENTRALDASHBOARD-6514845
- published 31 Mar 2024
- disclosed 25 Mar 2024
Introduced: 25 Mar 2024
CVE-2024-29041 Open this link in a new tabHow to fix?
Upgrade Wolfi
kubeflow-centraldashboard
to version 1.8.0-r3 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kubeflow-centraldashboard
package and not the kubeflow-centraldashboard
package as distributed by Wolfi
.
See How to fix?
for Wolfi
relevant fixed versions and status.
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode using encodeurl
on the contents before passing it to the location
header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is res.location()
but this is also called from within res.redirect()
. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.
References
- https://expressjs.com/en/4x/api.html#res.location
- https://github.com/expressjs/express/commit/0867302ddbde0e9463d0564fea5861feb708c2dd
- https://github.com/expressjs/express/commit/0b746953c4bd8e377123527db11f9cd866e39f94
- https://github.com/expressjs/express/pull/5539
- https://github.com/expressjs/express/security/advisories/GHSA-rv95-896h-c2vc
- https://github.com/koajs/koa/issues/1800