Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-3787-6prv-h9w3: Undici proxy-authorization header not cleared on cross-origin redirect in fetch

Impact

Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization headers.

Patches

This is patched in v5.28.3 and v6.6.1

Workarounds

There are no known workarounds.

References

  • https://fetch.spec.whatwg.org/#authentication-entries
  • https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g
ghsa
#nodejs#js#git#auth

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

Low severity GitHub Reviewed Published Feb 16, 2024 in nodejs/undici • Updated Feb 16, 2024

ghsa: Latest News

GHSA-g85v-wf27-67xc: Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`