Логотип exploitDog
bind:CVE-2020-11021
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11021

Количество 2

Количество 2

nvd логотип

CVE-2020-11021

почти 6 лет назад

Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-9w6v-m7wp-jwg4

почти 6 лет назад

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-11021

Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.

CVSS3: 6.3
0%
Низкий
почти 6 лет назад
github логотип
GHSA-9w6v-m7wp-jwg4

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

CVSS3: 6.3
0%
Низкий
почти 6 лет назад

Уязвимостей на страницу