CVE-2024-28849
MediumAdvisory
Published 14 Mar 2024In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.010
- 62nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 230
- of 17,781 indexed, latest versions
- Container images
- 221
- deployed by those charts
- Fix available
- 1 of 1
- affected package
follow-redirects' Proxy-Authorization header kept across hosts
Carried by container images the latest versions of 230 of 17,781 indexed charts deploy, on 221 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| follow-redirectsnpm | 1.0.0, 1.2.5, 1.5.10, 1.6.1+22 more | 1.15.6 | 221 |
- OSV records
- GHSA-cxjh-pqwp-8mfp
Charts affected
230 by stars
Container images carrying it
221 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| polonel/ | 0cf6513f6fe3 | follow-redirects | 1.15.6 | 1 |
| redis/ | 699d341bd329 | follow-redirects | 1.15.6 | 1 |
| requarks/ | 8b5865a7386c | follow-redirects | 1.15.6 | 1 |
| roadiehq/ | ef355bf5b639 | follow-redirects | 1.15.6 | 1 |
| samajh/ | ea742b4372ad | follow-redirects | 1.15.6 | 1 |
| samajh/ | 05ef4fddbb75 | follow-redirects | 1.15.6 | 1 |
| shinobisystems/ | 3ca746937856 | follow-redirects | 1.15.6 | 1 |
| shinobisystems/ | c2f5ce2e1067 | follow-redirects | 1.15.6 | 1 |
| siscc/ | b6f9a7c888fc | follow-redirects | 1.15.6 | 1 |
| socialmediamacroscope/ | c5095e94bc65 | follow-redirects | 1.15.6 | 1 |
| someblackmagic/ | 78bf43744ea5 | follow-redirects | 1.15.6 | 1 |
| someblackmagic/ | 88351d85c04c | follow-redirects | 1.15.6 | 1 |
| sqlpad/ | d3d2f430dffd | follow-redirects | 1.15.6 | 1 |
| stanfordoval/ | 1a63cdccedaf | follow-redirects | 1.15.6 | 1 |
| testhubio/ | e86c2db53be8 | follow-redirects | 1.15.6 | 1 |
| thecodingmachine/ | 64001369dad5 | follow-redirects | 1.15.6 | 1 |
| thecodingmachine/ | 5bdab56da2fa | follow-redirects | 1.15.6 | 1 |
| thecodingmachine/ | d8f66979b9b4 | follow-redirects | 1.15.6 | 1 |
| thecodingmachine/ | 3ccd467543b3 | follow-redirects | 1.15.6 | 1 |
| thingsboard/ | 57f98ed53b3d | follow-redirects | 1.15.6 | 1 |
| thingsboard/ | d388378062cc | follow-redirects | 1.15.6 | 1 |
| tooljet/ | c85a4720e42e | follow-redirects | 1.15.6 | 1 |
| tzahi12345/ | 3720b856bd2f | follow-redirects | 1.15.6 | 1 |
| vabene1111/ | ec4e9e2905b0 | follow-redirects | 1.15.6 | 1 |
| vlebediantsev/ | 007c6670ff48 | follow-redirects | 1.15.6 | 1 |
| vlebediantsev/ | 945675fd2636 | follow-redirects | 1.15.6 | 1 |
| vlebediantsev/ | 54f69d116c50 | follow-redirects | 1.15.6 | 1 |
| wazuh/ | 1787550d2358 | follow-redirects | 1.15.6 | 1 |
| winfred008/ | 10a68de5b398 | follow-redirects | 1.15.6 | 1 |
| xom4ekp2p/ | 2745b5fd8785 | follow-redirects | 1.15.6 | 1 |
| ymuski/ | 67819ca511b5 | follow-redirects | 1.15.6 | 1 |
| youssef11gaber10/ | ba6853e35c60 | follow-redirects | 1.15.6 | 1 |
| zooz/ | f491d1f7a865 | follow-redirects | 1.15.6 | 1 |
| zwavejs/ | 15a6040fb468 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 140aed2752c3 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | a52dc5db694a | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 985456bdfb46 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | c8a0d5ec5a12 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 0635f17c9d2c | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | e34964e336c1 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 0c5a3398d1e4 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 8ba040e79ca0 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | cc9498b64b5b | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | a8d40779eeae | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 5a9216989707 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 38a4f32fad82 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 4ddbb244c82f | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | e106681e7673 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | ef768f3df5d0 | follow-redirects | 1.15.6 | 1 |
| ghcr.io/ | 58d377933678 | follow-redirects | 1.15.6 | 1 |