undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
Summary
Two issues in undici's cache interceptor, both fixed by the same patch on `lib/util/cache.js`:
1. **Shared-cache disclosure:** Responses with malformed qualified `Cache-Control: private` directives such as `private=""` or `private=","` can be incorrectly stored in the default shared cache, then served to a later caller with the same cache key.
2. **Parse-time crash:** Mixed unqualified-and-qualified `private` directives in the same header (such as `public, max-age=60, private, private="hdr"`) cause an uncaught `TypeError` in the cache-control parser, terminating the request.
Impact
Shared-cache disclosure
Applications using `interceptors.cache()` in shared mode may cache a user-specific response and serve it to a later caller with the same cache key. This can disclose private response bodies and headers, including `Set-Cookie`.
Required conditions:
- the cache interceptor is enabled in shared mode, including the default configuration;
- an upstream returns a malformed directive such as `Cache-Control: public, max-age=300, private=""`;
- another request later matches the same cache key, without a separating `Vary` header.
Parse-time crash
Weakness classes: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) · CWE-248 (Uncaught Exception) · CWE-525 (Use of Web Browser Cache Containing Sensitive Information)
Source: GHSA-4cwx-7wf7-3272 · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page