LOW 3.9 npm

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

GHSA-3787-6prv-h9w3 · CVE-2024-24758

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization headers.

Patches

This is patched in v5.28.3 and v6.6.1

Workarounds

There are no known workarounds.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes