Insufficient verification of data authenticity in undici - CVE-2024-30261

 

Insufficient verification of data authenticity in undici - CVE-2024-30261

Published: April 5, 2024


Vulnerability identifier: #VU88178
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2024-30261
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the application does not verify authenticity of data. A remote attacker can alter the "integrity" option passed to fetch(), allowing fetch() to accept requests as valid even if they have been tampered.


Affected software

undici
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
Web and Scripting Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP4 LTSS
openSUSE Leap
openEuler
Red Hat OpenShift Dev Spaces
IBM Decision Optimization for Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
App Connect Enterprise Certified Container
IBM Cloud Pak for Business Automation
IBM Cloud Pak for Watson AIOps
Cloud Pak for Data
npm
v8-devel
nodejs16-devel
nodejs16-docs
nodejs16-debuginfo
nodejs16-debugsource
nodejs16
npm16
corepack16
nodejs18-debuginfo
nodejs18-docs
nodejs18
npm18
nodejs18-debugsource
nodejs18-devel
corepack18
nodejs-debuginfo
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs-debugsource
nodejs
nodejs20-debugsource
nodejs20
nodejs20-docs
corepack20
npm20
nodejs20-devel
nodejs20-debuginfo

How to mitigate CVE-2024-30261

Install updates from vendor's website.

undici - addressed in versions 5.28.4, 6.11.1
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Cloud Pak for Data - update to 4.8.5
IBM Decision Optimization for Cloud Pak for Data - update to 5.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.0.1
App Connect Enterprise Certified Container - addressed in versions 5.0.17, 11.5.0
npm - update to 10.5.0-1.20.12.1.1
v8-devel - update to 11.3.244.8-1.20.12.1.1
nodejs16-devel - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-docs - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-debuginfo - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16-debugsource - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
nodejs16 - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
npm16 - addressed in versions 16.20.2-8.45.1, 16.20.2-150400.3.36.1
corepack16 - update to 16.20.2-150400.3.36.1
nodejs18-debuginfo - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-docs - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18 - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
npm18 - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-debugsource - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
nodejs18-devel - addressed in versions 18.20.1-8.21.1, 18.20.1-150400.9.21.3
corepack18 - update to 18.20.1-150400.9.21.3
nodejs-debuginfo - update to 20.12.1-1
nodejs-docs - update to 20.12.1-1
nodejs-libs - update to 20.12.1-1
nodejs-full-i18n - update to 20.12.1-1
nodejs-devel - update to 20.12.1-1
nodejs-debugsource - update to 20.12.1-1
nodejs - update to 20.12.1-1
nodejs20-debugsource - update to 20.12.1-150500.11.9.2
nodejs20 - update to 20.12.1-150500.11.9.2
nodejs20-docs - update to 20.12.1-150500.11.9.2
corepack20 - update to 20.12.1-150500.11.9.2
npm20 - update to 20.12.1-150500.11.9.2
nodejs20-devel - update to 20.12.1-150500.11.9.2
nodejs20-debuginfo - update to 20.12.1-150500.11.9.2
nodejs20 - update to 20.12.2-1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins