vulnerability
Red Hat JBoss EAP: CVE-2024-30261: Improper Access Control
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:N/AC:H/Au:S/C:N/I:P/A:N) | Apr 4, 2024 | Sep 19, 2024 | Nov 26, 2025 |
Severity
2
CVSS
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
Published
Apr 4, 2024
Added
Sep 19, 2024
Modified
Nov 26, 2025
Description
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.. A flaw was found in the nodejs-undici package. This issue may allow an attacker to alter the integrity option passed to fetch(), allowing fetch() to accept requests as valid even if they have been tampered with.
Solution
red-hat-jboss-eap-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.