Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2024-02610

больше 2 лет назад

Уязвимость модуля Node.js follow-redirects, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-28849

больше 2 лет назад

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-28849

больше 2 лет назад

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-28849

больше 2 лет назад

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-28849

6 месяцев назад

Proxy-Authorization header kept across hosts in follow-redirects

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-28849

больше 2 лет назад

follow-redirects is an open source, drop-in replacement for Node's `ht ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cxjh-pqwp-8mfp

больше 2 лет назад

follow-redirects' Proxy-Authorization header kept across hosts

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02610

Уязвимость модуля Node.js follow-redirects, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-28849

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-28849

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28849

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-28849

Proxy-Authorization header kept across hosts in follow-redirects

CVSS3: 6.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2024-28849

follow-redirects is an open source, drop-in replacement for Node's `ht ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-cxjh-pqwp-8mfp

follow-redirects' Proxy-Authorization header kept across hosts

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу