Описание
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1.
A flaw was found in React Router. Insufficient Cross-Site Request Forgery (CSRF) checks in the framework mode allow a remote attacker to bypass these protections on PUT, PATCH, and DELETE requests. This could lead to a low integrity impact, where an attacker might be able to perform unintended actions on behalf of a user. Modern browser security features, such as Cross-Origin Resource Sharing (CORS) preflight and SameSite cookies, significantly limit the practical exploitability of this vulnerability.
Отчет
This is a Low impact vulnerability. Insufficient Cross-Site Request Forgery (CSRF) checks in React Router's framework mode could allow an attacker to bypass protections on PUT, PATCH, and DELETE requests. However, modern browser security features like CORS preflight and SameSite cookies significantly reduce the practical exploitability of this flaw in typical Red Hat deployments.
Меры по смягчению последствий
Red Hat products that ship react-router are affected by this CSRF bypass in Framework Mode on PUT, PATCH, and DELETE requests. However, modern browser protections — CORS preflight checks and SameSite cookie defaults — significantly limit the practical exploitability of this flaw. No specific workaround is required. Updating to react-router 7.15.1 or later, when available in product updates, will fully resolve this issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| A-MQ Interconnect 1 | qpid-dispatch | Not affected | ||
| Cryostat 4 | cryostat-openshift-console-plugin-npm | Not affected | ||
| Cryostat 4 | grafana-infinity-datasource-npm | Not affected | ||
| Cryostat 4 | react-router | Not affected | ||
| Cryostat 4 | react-router-dom | Not affected | ||
| Cryostat 4 | react-router-dom-v5-compat | Not affected | ||
| Exploit Intelligence | exploit-intelligence-tech-preview/agent-client-rhel9 | Fix deferred | ||
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Not affected | ||
| Migration Toolkit for Applications 8 | mta/mta-ui-rhel8 | Not affected | ||
| Migration Toolkit for Applications 8 | mta/mta-ui-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE requests. This is a low severity vulnerability because modern browser protections (CORS preflight, SameSite cookies) already block the cross-origin attack vectors that this missing CSRF check would otherwise gate. This vulnerability is fixed in 7.15.1.
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
EPSS
3.1 Low
CVSS3