Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30260

Опубликовано: 04 апр. 2024
Источник: redhat
CVSS3: 3.9
EPSS Низкий

Описание

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for fetch(), but did not clear them for undici.request(). This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

A flaw was found in the nodejs-undici package. Proxy-Authorization headers are not cleared on cross-origin redirects, which can allow for the exposure of sensitive data or allow an attacker to capture the persistent proxy-authentication header.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs-undiciNot affected
Red Hat OpenShift Dev Spaces 3 Containersdevspaces/dashboard-rhel8FixedRHSA-2024:666712.09.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=2273522nodejs-undici: proxy-authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

EPSS

Процентиль: 41%
0.00188
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 3.9
nvd
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 4.3
msrc
около 1 года назад

Описание отсутствует

CVSS3: 3.9
debian
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici ...

CVSS3: 3.9
github
почти 2 года назад

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

EPSS

Процентиль: 41%
0.00188
Низкий

3.9 Low

CVSS3