Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-30260

Опубликовано: 18 дек. 2024
Источник: msrc
CVSS3: 4.3
EPSS Низкий

Описание

Описание отсутствует

EPSS

Процентиль: 51%
0.00734
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 3.9
redhat
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 3.9
nvd
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 3.9
debian
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici ...

CVSS3: 3.9
github
больше 2 лет назад

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

EPSS

Процентиль: 51%
0.00734
Низкий

4.3 Medium

CVSS3