Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-30261

Опубликовано: 14 апр. 2024
Источник: msrc
CVSS3: 3.5
EPSS Низкий

Описание

Описание отсутствует

EPSS

Процентиль: 54%
0.00803
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
redhat
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
nvd
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
debian
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An att ...

CVSS3: 2.6
github
больше 2 лет назад

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

EPSS

Процентиль: 54%
0.00803
Низкий

3.5 Low

CVSS3