ZÉROJOUR

The zero-day paper — printed from structured content, not scraped prose.
Permanent editionPublic dataset · Sanity GROQGHSA × CISA KEV
node-fetch (npm) · published 2022-01-21

node-fetch forwards secure headers to untrusted sites

CVE-2022-0235 — CVSS 8.8/10. Fix: upgrade to 3.1.1.
Package
node-fetch
Ecosystem
npm
Vector
NETWORK
Complexity
LOW
Privileges
LOW
Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, & `cookie2` when redirecting to a untrusted site.

Weakness classes: CWE-173 (Improper Handling of Alternate Encoding) · CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) · CWE-601 (URL Redirection to Untrusted Site ('Open Redirect'))

Source: GHSA-r683-j2x4-v87g · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page

ZéroJour prints itself from a Sanity dataset of real advisories (GitHub Advisory Database, CC-BY-4.0; CISA KEV). No scraping, no keyword search — headlines are typed fields, scores are numbers, fixes are versions. The newsroom composes, a human approves.