digitalbazaar / digitalbazaar/http-client

CVE: 2024-24750 in undici

Open
#44 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
2
Forks
8
PR merge metrics
No merged PRs in 30d

Description

The undici team asserts that this CVE only affects versions >= 6.0.0 and that the v5.x release is not impacted.

https://github.com/nodejs/undici/issues/2789

If this is true, then the PR here that upgrades undici from v5 to v6 is not required to address this CVE.

https://github.com/digitalbazaar/http-client/pull/42

Some vulnerability scanning tools (e.g. Veracode) rely on NVD as the source of truth wrt assessing impacted versions. This CVE is currently "Awaiting Analysis" at NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-24750

We will continue testing the undici v6 upgrade while NVD performs their analysis.

20240306 - Still waiting analysis.
20240311 - Still waiting analysis.
20240319 - Still waiting analysis.
20240327 - Still waiting analysis.
20240703 - Still waiting analysis.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the undici issue 2789, the referenced PR 42, and the NVD entry for CVE-2024-24750, then verify whether undici v5 is affected. Done means documenting the confirmed impact and deciding whether the v6 upgrade is required for this vulnerability.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.