Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-24750

Опубликовано: 16 фев. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling fetch(url) and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*
Версия от 6.0.0 (включая) до 6.6.1 (исключая)

EPSS

Процентиль: 51%
0.007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
redhat
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In affected versions calling `fetch(url)` and not consuming the incoming body ((or consuming it very slowing) will lead to a memory leak. This issue has been addressed in version 6.6.1. Users are advised to upgrade. Users unable to upgrade should make sure to always consume the incoming body.

CVSS3: 6.5
debian
больше 2 лет назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. In aff ...

CVSS3: 6.5
github
больше 2 лет назад

fetch(url) leads to a memory leak in undici

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость функции fetch() клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 51%
0.007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400
CWE-401