Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-8129

Опубликовано: 25 июл. 2025
Источник: redhat
CVSS3: 6.1

Описание

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

A flaw was found in Koa. An issue was discovered in the back redirect functionality, used for redirect operations. This issue allows an attacker to manipulate the Referer header to force a user’s browser to navigate to an external, potentially malicious website due to an insecure implementation. This issue allows attackers to perform phishing, social engineering, or other redirect-based attacks on users of affected applications.

Отчет

To exploit this flaw, an attacker needs to convince a user into visiting a malicious link, limiting the possibility of exploitation. However, this vulnerability still has a moderate severity due to the impact of redirect-based attacks.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2openshift-service-mesh/grafana-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-cni-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-must-gather-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-operator-bundleFix deferred
OpenShift Service Mesh 2openshift-service-mesh/istio-rhel8-operatorFix deferred
OpenShift Service Mesh 2openshift-service-mesh/pilot-rhel8Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/proxyv2-rhel9Fix deferred
OpenShift Service Mesh 2openshift-service-mesh/ratelimit-rhel8Fix deferred
OpenShift Service Mesh 3openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/istio-cni-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2383344koa: KoaJS Koa HTTP Header response.js back redirect

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.5
nvd
8 месяцев назад

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 3.5
debian
8 месяцев назад

A vulnerability, which was classified as problematic, was found in Koa ...

CVSS3: 3.5
github
8 месяцев назад

Koa Open Redirect via Referrer Header (User-Controlled)

6.1 Medium

CVSS3