CVE-2022-24822
Summary
| CVE | CVE-2022-24822 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-06 18:15:00 UTC |
| Updated | 2022-04-14 17:26:00 UTC |
| Description | Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @podium/proxy is a module for proxying HTTP requests from a layout server to a podlet server. In @podium/layout prior to version 4.6.110 and @podium/proxy prior to version 4.2.74, an attacker using the `Trailer` header as part of the request against proxy endpoints has the ability to take down the server. All Podium layouts that include podlets with proxy endpoints are affected. `@podium/layout`, which is the main way developers/users are vulnerable to this exploit, has been patched in version `4.6.110`. All earlier versions are vulnerable.`@podium/proxy`, which is the source of the vulnerability and is used by `@podium/layout` has been patched in version `4.2.74`. All earlier versions are vulnerable. It is not easily possible to work around this issue without upgrading. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Finn | Podium Layout | All | All | All | All |
| Application | Finn | Podium Proxy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Denial of Service vulnerability in @podium/layout and @podium/proxy · Advisory · podium-lib/proxy · GitHub | CONFIRM | github.com | |
| fix: remove trailer header if present when proxying · podium-lib/proxy@9698a40 · GitHub | MISC | github.com | |
| Release v4.6.110 · podium-lib/layout · GitHub | MISC | github.com | |
| fix: update Proxy module to fix trailer header vulnerability · podium-lib/layout@fe43e65 · GitHub | MISC | github.com | |
| Release v4.2.74 · podium-lib/proxy · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.