Junglewise Threat Intelligence

CVE-2024-30260: Undici Proxy-Authorization header leak on cross-origin redirect

CVE-2024-30260 · Severity: low · CVSS 3.1 · Published 2024-04-04

Executive brief

Undici is a popular HTTP client library for Node.js used by many web applications and services. When performing cross-origin redirects (following HTTP redirects to different domains), Undici's request methods (dispatch, request, stream, pipeline) fail to remove the Proxy-Authorization header before sending the request to the new domain. This could allow a malicious attacker controlling an intermediate proxy to capture proxy authentication credentials intended for a legitimate proxy server.

Technical details

This vulnerability is an information disclosure flaw (CWE-200) where sensitive authentication headers are leaked across security boundaries. The root cause is incomplete header sanitization in Undici's redirect handling logic—while the fetch() API correctly clears both Authorization and Proxy-Authorization headers on cross-origin redirects per the Fetch Standard, the lower-level undici.request(), dispatch(), stream(), and pipeline() methods do not. An attacker can exploit this by setting up a cross-origin redirect (e.g., from origin A to origin B) and capturing the Proxy-Authorization header when the second request is made. Exploitation requires the attacker to control a cross-origin server and the user to initiate a request with redirects enabled (maxRedirections > 0). The vulnerability was patched in versions 5.28.4 and 6.11.1.

Affected products

  • Node.js undici <5.28.4; >=6.0.0 <6.11.1

Timeline

  • 2024-04-04: disclosed
  • 2024-04-04: patched: Fixed in v5.28.4 and v6.11.1

References