Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0155

Опубликовано: 10 янв. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

A flaw was found in follow-redirects when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 1npm-follow-redirectsOut of support scope
OpenShift Service Mesh 2.0npm-follow-redirectsAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-header-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/kui-web-terminal-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Affected
Red Hat Advanced Cluster Security 3follow-redirectsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-359
https://bugzilla.redhat.com/show_bug.cgi?id=2044556follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor

EPSS

Процентиль: 80%
0.01302
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVSS3: 6.5
nvd
около 4 лет назад

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVSS3: 6.5
debian
около 4 лет назад

follow-redirects is vulnerable to Exposure of Private Personal Informa ...

CVSS3: 8
github
около 4 лет назад

Exposure of sensitive information in follow-redirects

CVSS3: 8
fstec
около 4 лет назад

Уязвимость модуля Node.js follow-redirects, связанная с ошибками обработки файлов cookie, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 80%
0.01302
Низкий

6.5 Medium

CVSS3