digitalbazaar / digitalbazaar/http-client
CVE: 2024-24750 in undici
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 2
- Forks
- 8
- PR merge metrics
- No merged PRs in 30d
Description
The undici team asserts that this CVE only affects versions >= 6.0.0 and that the v5.x release is not impacted.
https://github.com/nodejs/undici/issues/2789
If this is true, then the PR here that upgrades undici from v5 to v6 is not required to address this CVE.
https://github.com/digitalbazaar/http-client/pull/42
Some vulnerability scanning tools (e.g. Veracode) rely on NVD as the source of truth wrt assessing impacted versions. This CVE is currently "Awaiting Analysis" at NVD
https://nvd.nist.gov/vuln/detail/CVE-2024-24750
We will continue testing the undici v6 upgrade while NVD performs their analysis.
20240306 - Still waiting analysis.
20240311 - Still waiting analysis.
20240319 - Still waiting analysis.
20240327 - Still waiting analysis.
20240703 - Still waiting analysis.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the undici issue 2789, the referenced PR 42, and the NVD entry for CVE-2024-24750, then verify whether undici v5 is affected. Done means documenting the confirmed impact and deciding whether the v6 upgrade is required for this vulnerability.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100