Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-24750

Опубликовано: 16 фев. 2024
Источник: debian

Описание

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-undicinot-affectedpackage

Примечания

  • https://github.com/nodejs/undici/security/advisories/GHSA-9f24-jqhm-jfcw

  • https://github.com/nodejs/undici/commit/87a48113f1f68f60aa09abb07276d7c35467c663 (v6.6.1)

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
redhat
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
nvd
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
github
больше 2 лет назад

fetch(url) leads to a memory leak in undici

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функции fetch() клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании