<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2022-31151</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2022-31151</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>4</Number>
        <Date>2022-12-13T00:41:16Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-07-21T23:35:22Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-12-13T00:41:16Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2022-31151</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site. This was patched in v5.7.1. By default, this vulnerability is not exploitable. Do not enable redirections, i.e. `maxRedirections: 0` (the default).</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 7.1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12" CPE="cpe:/o:suse:sle-module-web-scripting:12">SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 4.2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 4.3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Retail Branch Server 4.2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Retail Branch Server 4.3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp3">SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 4.3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4" CPE="cpe:/o:suse:sle-module-web-scripting:15:sp4">SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="nodejs16">
      <FullProductName ProductID="nodejs16" CPE="cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*">nodejs16</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs16-devel">
      <FullProductName ProductID="nodejs16-devel">nodejs16-devel</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nodejs16-docs">
      <FullProductName ProductID="nodejs16-docs">nodejs16-docs</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="npm16">
      <FullProductName ProductID="npm16">npm16</FullProductName>
    </Branch>
    <Relationship ProductReference="nodejs16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16">nodejs16 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16-devel">nodejs16-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16-docs">nodejs16-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 12:npm16">npm16 as a component of SUSE Linux Enterprise Module for Web and Scripting 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16">nodejs16 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16-devel">nodejs16-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16-docs">nodejs16-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP3:npm16">npm16 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16">nodejs16 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-devel" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16-devel">nodejs16-devel as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="nodejs16-docs" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16-docs">nodejs16-docs as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="npm16" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Web and Scripting 15 SP4">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Web and Scripting 15 SP4:npm16">npm16 as a component of SUSE Linux Enterprise Module for Web and Scripting 15 SP4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker who can control the redirection target (ie. an open redirector) to leak the cookie to the 3rd party site. This was patched in v5.7.1. By default, this vulnerability is not exploitable. Do not enable redirections, i.e. `maxRedirections: 0` (the default).</Note>
    </Notes>
    <CVE>CVE-2022-31151</CVE>
    <ProductStatuses>
      <Status Type="Known Not Affected">
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:nodejs16-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 12:npm16</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP3:nodejs16-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP3:npm16</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16-devel</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP4:nodejs16-docs</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Web and Scripting 15 SP4:npm16</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>3.7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
