QID 995583

Date Published: 2023-10-17

QID 995583: NodeJs (Npm) Security Update for undici (GHSA-wqq4-5wpv-mx2g)

Undici clears Authorization headers on cross-origin redirects, but does not clear Cookie headers. By design, cookie headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since Undici handles headers more liberally than the specification, there was a disconnect from the assumptions the spec made, and Undici's implementation of fetch.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 3.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-wqq4-5wpv-mx2g for updates and patch information.
    Vendor References

    CVEs related to QID 995583

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wqq4-5wpv-mx2g undici URL Logo github.com/advisories/GHSA-wqq4-5wpv-mx2g