Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0235

Опубликовано: 14 янв. 2022
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

A flaw was found in node-fetch. When following a redirect to a third-party domain, node-fetch was forwarding sensitive headers such as "Authorization," "WWW-Authenticate," and "Cookie" to potentially untrusted targets. This flaw leads to the exposure of sensitive information to an unauthorized actor.

Отчет

This flaw is out of support scope for dotnet-5.0. For more information about Dotnet product support scope, please see https://access.redhat.com/support/policy/updates/net-core

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Distributed Tracing Jaeger 1distributed-tracing/jaeger-all-in-one-rhel8Not affected
Distributed Tracing Jaeger 1distributed-tracing/jaeger-query-rhel8Affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Will not fix
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-dotnetWill not fix
.NET Core 5.0 on Red Hat Enterprise Linuxrh-dotnet50-dotnetOut of support scope
OpenShift Developer Tools and ServicesodoAffected
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2044591node-fetch: exposure of sensitive information to an unauthorized actor

EPSS

Процентиль: 71%
0.00647
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 4 лет назад

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 6.1
nvd
около 4 лет назад

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS3: 6.1
debian
около 4 лет назад

node-fetch is vulnerable to Exposure of Sensitive Information to an Un ...

CVSS3: 8.8
github
около 4 лет назад

node-fetch forwards secure headers to untrusted sites

suse-cvrf
почти 4 года назад

Security update for nodejs8

EPSS

Процентиль: 71%
0.00647
Низкий

6.1 Medium

CVSS3