LOW 3.9 npm

Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline

GHSA-m4v8-wqvr-p9f7 · CVE-2024-30260

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Undici cleared Authorization and Proxy-Authorization headers for fetch(), but did not clear them for undici.request().

Patches

This has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.
Fixes has been released in v5.28.4 and v6.11.1.

Workarounds

use fetch() or disable maxRedirections.

References

Linzi Shang reported this.

Ready to move

Start Securing

Free, no credit card | First findings in minutes