LOW 3.9 npm
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
GHSA-m4v8-wqvr-p9f7 · CVE-2024-30260
Published · Modified
Description
Impact
Undici cleared Authorization and Proxy-Authorization headers for fetch(), but did not clear them for undici.request().
Patches
This has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.
Fixes has been released in v5.28.4 and v6.11.1.
Workarounds
use fetch() or disable maxRedirections.
References
Linzi Shang reported this.
References
- WEB https://github.com/nodejs/undici/security/advisories/GHSA-m4v8-wqvr-p9f7
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-30260
- WEB https://github.com/nodejs/undici/commit/64e3402da4e032e68de46acb52800c9a06aaea3f
- WEB https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75
- WEB https://hackerone.com/reports/2408074
- PACKAGE https://github.com/nodejs/undici
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HQVHWAS6WDXXIU7F72XI55VZ2LTZUB33
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NC3V3HFZ5MOJRZDY5ZELL6REIRSPFROJ
- WEB https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E
- WEB https://security.netapp.com/advisory/ntap-20240905-0008
Ready to move
Start Securing
Free, no credit card | First findings in minutes