vulnerability

Red Hat JBoss EAP: CVE-2024-30261: Improper Access Control

Severity
2
CVSS
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
Published
Apr 4, 2024
Added
Sep 19, 2024
Modified
Nov 26, 2025

Description

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.. A flaw was found in the nodejs-undici package. This issue may allow an attacker to alter the integrity option passed to fetch(), allowing fetch() to accept requests as valid even if they have been tampered with.

Solution

red-hat-jboss-eap-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.