VDB
BDU:2024-08734
BDU:2024-08734
PUBLISHED
CVSS 6.5 MEDIUM
Уязвимость метода undici.request клиента HTTP/1.1 Undici программной платформы Node.js, позволяющая нарушителю внедрить произвольные HTTP-заголовки
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Node.js Foundation | Red Hat Enterprise Linux, Debian GNU/Linux, Node.js, Undici | |
| nodejs | undici | * |
Timeline
- Mar 1, 2024 PoC Published
- Jul 17, 2024 PoC Published
- Oct 29, 2024 CVE Published
- Aug 13, 2025 CVE Updated
- Mar 20, 2026 PoC Published
- Mar 28, 2026 PoC Published
References
- https://github.com/nodejs/undici/security/advisories/GHSA-5r9g-qh6m-jxff url
- https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/ url
- https://security-tracker.debian.org/tracker/CVE-2023-23936 advisory
- https://github.com/nodejs/undici/releases/tag/v5.19.1 url
- https://hackerone.com/reports/1820955 url
- https://github.com/nodejs/undici/tree/main/docs url
- https://github.com/nodejs/undici/commit/a2eff05401358f6595138df963837c24348f2034 advisory
- https://access.redhat.com/security/cve/CVE-2023-23936 advisory