Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-30260

Опубликовано: 04 апр. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 3.9

Описание

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for fetch(), but did not clear them for undici.request(). This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

РелизСтатусПримечание
devel

not-affected

5.28.4+dfsg1+~cs23.12.11-2
esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

mantic

ignored

end of life, was needs-triage
noble

needs-triage

oracular

ignored

end of life, was needs-triage
plucky

not-affected

5.28.4+dfsg1+~cs23.12.11-2
questing

not-affected

5.28.4+dfsg1+~cs23.12.11-2

Показывать по

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
redhat
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 3.9
nvd
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

CVSS3: 4.3
msrc
около 1 года назад

Описание отсутствует

CVSS3: 3.9
debian
почти 2 года назад

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici ...

CVSS3: 3.9
github
почти 2 года назад

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

3.9 Low

CVSS3