CVE-2024-38372
EUVD-2024-223508.07.2024, 21:15
Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nodejs | undici | 6.14.0 ≤ 𝑥 < 6.19.2 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References