CVE-2024-30261
LOWNodejs Undici < 5.28.4 - Improper Access Control
Title source: ruleDescription
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
Scores
CVSS v3
2.6
EPSS
0.0008
EPSS Percentile
23.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Classification
CWE
CWE-284
Status
published
Affected Products (5)
nodejs/undici
< 5.28.4
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
npm/undici
< 5.28.4npm
Timeline
Published
Apr 04, 2024
Tracked Since
Feb 18, 2026