Skip to content

[Security] Upgrade Undici dependency to latest version #40

@Dieman89

Description

@Dieman89

Detailed paths

Introduced through: › [email protected][email protected]
Fix: Upgrade to [email protected]

Overview

undici is an An HTTP/1.1 client, written from scratch for Node.js

Affected versions of this package are vulnerable to Improper Certificate Validation due to Undici.ProxyAgent missing verification of the remote server's certificate, which leads to exposure of all the requests and responses data to the proxy.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions