CVE-2024-24750

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 16, 2024
Updated: Feb 20, 2024
CWE ID 400

Summary

CVE-2024-24750 is a vulnerability in Undici, an HTTP/1.1 client for Node.js. It affects certain versions of the software where calling fetch(url) without consuming the incoming body or doing so very slowly can result in a memory leak. The issue has been resolved in version 6.6.1, and users are advised to upgrade to this version. If upgrading is not possible, users should ensure that they always consume the incoming body. The vulnerability has a base severity of MEDIUM and an exploitability score of 2.8, with the potential for high availability impact on affected systems.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-24750 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options