QID 995583
Date Published: 2023-10-17
QID 995583: NodeJs (Npm) Security Update for undici (GHSA-wqq4-5wpv-mx2g)
Undici clears Authorization headers on cross-origin redirects, but does not clear Cookie headers. By design, cookie headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wqq4-5wpv-mx2g for updates and patch information.
Vendor References
- GHSA-wqq4-5wpv-mx2g -
github.com/advisories/GHSA-wqq4-5wpv-mx2g
CVEs related to QID 995583
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wqq4-5wpv-mx2g | undici |
|