Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0536

Опубликовано: 09 фев. 2022
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.

A flaw was found in the follow-redirects package. This flaw allows the exposure of sensitive information to an unauthorized actor due to the usage of insecure HTTP protocol. This issue happens with an Authorization header leak from the same hostname, https-http, and requires a Man-in-the-Middle (MITM) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Will not fix
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-dotnetOut of support scope
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Service Mesh 2.0kialiAffected
OpenShift Service Mesh 2.0servicemesh-grafanaAffected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-header-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-ui-rhel8Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200->CWE-212
https://bugzilla.redhat.com/show_bug.cgi?id=2053259follow-redirects: Exposure of Sensitive Information via Authorization Header leak

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
почти 4 года назад

Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.

CVSS3: 2.6
nvd
почти 4 года назад

Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.

CVSS3: 2.6
debian
почти 4 года назад

Improper Removal of Sensitive Information Before Storage or Transfer i ...

CVSS3: 5.9
github
почти 4 года назад

Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2022-0536