Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2024-30261

Опубликовано: 15 апр. 2024
Источник: msrc
CVSS3: 3.5
EPSS Низкий

Описание

Описание отсутствует

Возможность эксплуатации

DOS

N/A

EPSS

Процентиль: 24%
0.00081
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
redhat
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
nvd
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 2.6
debian
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. An att ...

CVSS3: 2.6
github
почти 2 года назад

Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect

EPSS

Процентиль: 24%
0.00081
Низкий

3.5 Low

CVSS3