Overview
About vulnerability
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici’s fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer’s view of a cookie’s SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie header, validate that the resulting sameSite attribute is one of ‘Strict’, ‘Lax’, or ‘None’ (exact, case-insensitive) before forwarding or relying on it.Details
- Affected product:
- AlmaLinux 9.2 ESU , AngularJS , Node.js , Protocol Buffers , React , TuxCare 9.6 ESU , Vue , api-extractor-model , astro , babel-loader , browser-sync , chrome-launcher , chromium-edge-launcher , cli , css-loader , css-minimizer-webpack-plugin , definitelytyped , del , dev-middleware , engine.io , esbuild-loader , extract-css-chunks-webpack-plugin , facebook/jest , facebook/metro , file-loader , file-system-cache , fork-ts-checker-webpack-plugin , friendly-errors-webpack-plugin , globby , got , happy-dom , hard-source-webpack-plugin , html-webpack-plugin , http-proxy-middleware , inquirer-external-editor , inquirer.js , jest , karma , karma-jasmine , karma-junit-reporter , karma-requirejs , metro , mini-css-extract-plugin , miniflare , minimizer-webpack-plugin , mongodb , mongodb-connection-string-url , mongoose , nguniversal , nuxt , parse5 , plugins , postcss-loader , pretty-format , remix , rollup , rollup-plugin-node-resolve , rollup-plugin-sourcemaps , rules_nodejs , rushstack , selfsigned , socket.io , sort-package-json , storybook , strong-error-handler , style-resources-loader , thread-loader , time-fix-plugin , ts-command-line , undici , url-loader , vanilla-extract , vite , vite-node , webpack , webpack-dev-middleware , webpack-dev-server , webpackbar , worker-loader , workers-sdk , xdm
- Affected packages:
- @remix-run/server-runtime @ 2.17.5 (+809 more)