QID 997962
Date Published: 2024-04-08
QID 997962: NodeJs (Npm) Security Update for undici (GHSA-9qxr-qj54-h672)
If an attacker can alter the integrity option passed to fetch(), they can let fetch() accept requests as valid even if they have been tampered.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9qxr-qj54-h672 for updates and patch information.
Vendor References
- GHSA-9qxr-qj54-h672 -
github.com/advisories/GHSA-9qxr-qj54-h672
CVEs related to QID 997962
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9qxr-qj54-h672 | undici |
|