Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-24750

Опубликовано: 16 фев. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling fetch(url) and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
Версия от 6.0.0 (включая) до 6.6.1 (исключая)

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
redhat
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
debian
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In aff ...

CVSS3: 6.5
github
почти 2 года назад

fetch(url) leads to a memory leak in undici

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость функции fetch() клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 54%
0.00315
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401