icon

We found results for “

CVE-2024-38372

Good to know:

icon
icon

Date: July 8, 2024

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Insertion of Sensitive Information Into Sent Data

CWE-201

Top Fix

icon

Upgrade Version

Upgrade to version undici - 6.19.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): HIGH
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us