Undici Patches Authentication Header Vulnerability
CVE-2024-24758

3.9LOW

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
16 February 2024

What is CVE-2024-24758?

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authentication headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected Version(s)

undici < 5.28.3 < 5.28.3

undici >= 6.0.0, < 6.6.1 < 6.0.0, 6.6.1

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.