node-fetch forwards secure headers to untrusted sites
CVE-2022-0235 — CVSS 8.8/10. Fix: upgrade to 3.1.1.
node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, & `cookie2` when redirecting to a untrusted site.
Weakness classes: CWE-173 (Improper Handling of Alternate Encoding) · CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) · CWE-601 (URL Redirection to Untrusted Site ('Open Redirect'))
Source: GHSA-r683-j2x4-v87g · GitHub Advisory Database (CC-BY-4.0) — printed from a structured Sanity dataset. ← Back to the front page