Количество 13
Количество 13
CVE-2024-24758
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-24758
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-24758
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-24758
Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici
CVE-2024-24758
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici ...
GHSA-3787-6prv-h9w3
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
BDU:2024-02800
Уязвимость клиента HTTP/1.1 Undici программной платформы Node.js, связанная с недостаточной защитой служебных данных в результате некорректной очистки заголовков Proxy-Authentication, позволяющая нарушителю повысить свои привилегии
SUSE-SU-2024:0731-1
Security update for nodejs16
SUSE-SU-2024:0729-1
Security update for nodejs16
SUSE-SU-2024:0728-1
Security update for nodejs16
SUSE-SU-2024:0730-1
Security update for nodejs18
SUSE-SU-2024:0644-1
Security update for nodejs18
SUSE-SU-2024:0643-1
Security update for nodejs20
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-24758 Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. | CVSS3: 3.9 | 0% Низкий | почти 2 года назад | |
CVE-2024-24758 Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. | CVSS3: 3.9 | 0% Низкий | почти 2 года назад | |
CVE-2024-24758 Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. | CVSS3: 3.9 | 0% Низкий | почти 2 года назад | |
CVE-2024-24758 Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undici | CVSS3: 4.5 | 0% Низкий | около 1 года назад | |
CVE-2024-24758 Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici ... | CVSS3: 3.9 | 0% Низкий | почти 2 года назад | |
GHSA-3787-6prv-h9w3 Undici proxy-authorization header not cleared on cross-origin redirect in fetch | CVSS3: 3.9 | 0% Низкий | почти 2 года назад | |
BDU:2024-02800 Уязвимость клиента HTTP/1.1 Undici программной платформы Node.js, связанная с недостаточной защитой служебных данных в результате некорректной очистки заголовков Proxy-Authentication, позволяющая нарушителю повысить свои привилегии | CVSS3: 3.9 | 0% Низкий | около 2 лет назад | |
SUSE-SU-2024:0731-1 Security update for nodejs16 | почти 2 года назад | |||
SUSE-SU-2024:0729-1 Security update for nodejs16 | почти 2 года назад | |||
SUSE-SU-2024:0728-1 Security update for nodejs16 | почти 2 года назад | |||
SUSE-SU-2024:0730-1 Security update for nodejs18 | почти 2 года назад | |||
SUSE-SU-2024:0644-1 Security update for nodejs18 | почти 2 года назад | |||
SUSE-SU-2024:0643-1 Security update for nodejs20 | почти 2 года назад |
Уязвимостей на страницу