Description
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
References (8)
Core 8
Core References
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240905-0008/
Vendor Advisory x_refsource_confirm
https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672
Patch x_refsource_misc
https://github.com/nodejs/undici/commit/2b39440bd9ded841c93dd72138f3b1763ae26055
Patch x_refsource_misc
https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3
Exploit, Issue Tracking x_refsource_misc
https://hackerone.com/reports/2377760
Scores
CVSS v3
2.6
EPSS
0.0006
EPSS Percentile
18.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (5)
fedoraproject/fedora
38
fedoraproject/fedora
39
fedoraproject/fedora
40
nodejs/undici
< 5.28.4
npm/undici
0 - 5.28.4npm
Published
Apr 04, 2024
Tracked Since
Feb 18, 2026