Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36437
HistoryJul 22, 2022 - 8:40 a.m.

Open Redirect

2022-07-2208:40:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.001 Low

EPSS

Percentile

41.3%

undici is vulnerable to open redirect. The vulnerability exists due to the insufficient checks in shouldRemoveHeader function, which results in accidental leakage of cookie headers, allowing an attacker to redirect the victim to an attacker controlled site.

CPENameOperatorVersion
undicile5.4.0
undicile5.7.0
undicile5.4.0
undicile5.7.0

0.001 Low

EPSS

Percentile

41.3%