Bugzilla – Bug 1222603
VUL-0: CVE-2024-30261: nodejs: fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Last modified: 2024-07-19 12:59:39 UTC
https://github.com/nodejs/undici/security/advisories/GHSA-9qxr-qj54-h672 Topic: fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect Package undici (npm) Affected versions < 5.28.3; > 6.0.0 <= 6.11.0 Patched versions >= 5.28.4 < 6.0.0; >= 6.11.1 Description: Impact: If an attacker can alter the integrity option passed to fetch(), they can let fetch() accept requests as valid even if they have been tampered. Patches: Fixed in d542b8c. Fixes has been released in v5.28.4 and v6.11.1. Workarounds: Ensure that integrity cannot be tampered with. References: https://hackerone.com/reports/2377760
This is an autogenerated message for OBS integration: This bug (1222603) was mentioned in https://build.opensuse.org/request/show/1166607 Factory / nodejs21
This is an autogenerated message for OBS integration: This bug (1222603) was mentioned in https://build.opensuse.org/request/show/1166624 Factory / nodejs20
SUSE-SU-2024:1301-1: An update that solves five vulnerabilities can now be installed. Category: security (important) Bug References: 1220053, 1222244, 1222384, 1222530, 1222603 CVE References: CVE-2024-24806, CVE-2024-27982, CVE-2024-27983, CVE-2024-30260, CVE-2024-30261 Maintenance Incident: [SUSE:Maintenance:33347](https://smelt.suse.de/incident/33347/) Sources used: Web and Scripting Module 15-SP5 (src): nodejs20-20.12.1-150500.11.9.2 openSUSE Leap 15.5 (src): nodejs20-20.12.1-150500.11.9.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:1309-1: An update that solves five vulnerabilities can now be installed. Category: security (important) Bug References: 1220053, 1222244, 1222384, 1222530, 1222603 CVE References: CVE-2024-24806, CVE-2024-27982, CVE-2024-27983, CVE-2024-30260, CVE-2024-30261 Maintenance Incident: [SUSE:Maintenance:33350](https://smelt.suse.de/incident/33350/) Sources used: openSUSE Leap 15.4 (src): nodejs18-18.20.1-150400.9.21.3 openSUSE Leap 15.5 (src): nodejs18-18.20.1-150400.9.21.3 Web and Scripting Module 15-SP5 (src): nodejs18-18.20.1-150400.9.21.3 SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src): nodejs18-18.20.1-150400.9.21.3 SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src): nodejs18-18.20.1-150400.9.21.3 SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src): nodejs18-18.20.1-150400.9.21.3 SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src): nodejs18-18.20.1-150400.9.21.3 SUSE Manager Server 4.3 (src): nodejs18-18.20.1-150400.9.21.3 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:1307-1: An update that solves five vulnerabilities can now be installed. Category: security (important) Bug References: 1220053, 1222244, 1222384, 1222530, 1222603 CVE References: CVE-2024-24806, CVE-2024-27982, CVE-2024-27983, CVE-2024-30260, CVE-2024-30261 Maintenance Incident: [SUSE:Maintenance:33351](https://smelt.suse.de/incident/33351/) Sources used: Web and Scripting Module 12 (src): nodejs18-18.20.1-8.21.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:1837-1: An update that solves two vulnerabilities can now be installed. Category: security (low) Bug References: 1222530, 1222603 CVE References: CVE-2024-30260, CVE-2024-30261 Maintenance Incident: [SUSE:Maintenance:34067](https://smelt.suse.de/incident/34067/) Sources used: openSUSE Leap 15.4 (src): nodejs16-16.20.2-150400.3.36.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2024:1836-1: An update that solves two vulnerabilities can now be installed. Category: security (low) Bug References: 1222530, 1222603 CVE References: CVE-2024-30260, CVE-2024-30261 Maintenance Incident: [SUSE:Maintenance:34069](https://smelt.suse.de/incident/34069/) Sources used: Web and Scripting Module 12 (src): nodejs16-16.20.2-8.45.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.