Описание
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-follow-redirects | fixed | 1.14.7+~1.13.1-1 | package | |
node-follow-redirects | fixed | 1.13.1-1+deb11u1 | bullseye | package |
node-follow-redirects | ignored | buster | package |
Примечания
https://huntr.dev/bounties/fc524e4b-ebb6-427d-ab67-a64181020406
https://github.com/follow-redirects/follow-redirects/issues/183
https://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22 (v1.14.7)
EPSS
Связанные уязвимости
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Exposure of sensitive information in follow-redirects
Уязвимость модуля Node.js follow-redirects, связанная с ошибками обработки файлов cookie, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS