PT-2024-2954 · Node.Js+3 · Undici+3

·

CVE-2024-30260

·

Published

2024-04-04

·

Updated

2026-08-25

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Undici versions prior to 5.28.4 Undici versions prior to 6.11.1
Description The issue is related to the Undici HTTP/1.1 client for Node.js, which has a flaw in its authorization procedure. Specifically, Undici clears Authorization and Proxy-Authorization headers for fetch(), but fails to do so for undici.request(). This could potentially allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 5.28.4, update to version 5.28.4 or later. For versions prior to 6.11.1, update to version 6.11.1 or later. As a temporary workaround, consider using fetch() instead of undici.request(). Alternatively, disable maxRedirections to minimize the risk of exploitation.

Exploit

Fix

Improper Authorization

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-39734
AZL-39803
BDU:2024-03121
CVE-2024-30260
GHSA-M4V8-WQVR-P9F7
OESA-2024-2174
OPENSUSE-SU-2024:13850-1
OPENSUSE-SU-2024:13851-1
OPENSUSE-SU-2024:13852-1
OPENSUSE-SU-2024_1301-1
OPENSUSE-SU-2024_1309-1
OPENSUSE-SU-2024_1837-1
SUSE-SU-2024:1301-1
SUSE-SU-2024:1307-1
SUSE-SU-2024:1309-1
SUSE-SU-2024:1836-1
SUSE-SU-2024:1837-1
SUSE-SU-2024_1836-1

Affected Products

Astra Linux
Debian
Suse
Undici