Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-24758

Published: February 16, 2024Last modified: May 22, 2024

Description

Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authentication` headers. This issue has been patched in versions 5.28.3 and 6.6.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Severity score breakdown

ParameterValue
Base score4.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredHIGH
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSnodejsFixed (18.19.1-r0)
StreamnodejsFixed (20.11.1-r0)
Liberica NIK23 (JDK 17)standard (nodejs)Fixed (23.0.4+1)
23 (JDK 21)standard (nodejs)Fixed (23.1.3+2)
24 (JDK 22)nodejsFixed (24.0.1+1)

References

Published BELL-SAs

ON THIS PAGE