Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1365

Опубликовано: 16 апр. 2022
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

A flaw was found in the cross-fetch library when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Service Mesh 2.0servicemesh-prometheusAffected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat 3scale API Management Platform 23amp-systemNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/search-ui-rhel8Affected
Red Hat Fuse 7cross-fetchNot affected
Red Hat JBoss Enterprise Application Platform 7cross-fetchNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-359
https://bugzilla.redhat.com/show_bug.cgi?id=2076133cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor

EPSS

Процентиль: 50%
0.00273
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 4 года назад

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.

CVSS3: 6.1
github
почти 4 года назад

Withdrawn Advisory: Incorrect Authorization in cross-fetch

CVSS3: 8.8
fstec
около 4 лет назад

Уязвимость API-интерфейса WHATWG Fetch для Node Cross-fetch, связанная с ошибками обработки файлов cookie, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 50%
0.00273
Низкий

7.1 High

CVSS3