GHSA-32x6-qvw6-mxj4
LOWCVE-2022-24719Using followRedirects or followRedirectsWith with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that includes confidential headers such as Authorization or Cookie, exposes you to a vulnerability where, if the destination server were to redirect the request to a server on a third-party domain, or the same domain over unencrypted HTTP, the headers wo
- Affected
- >= 4.0.0, < 4.0.2
- Fixed in
- 4.0.2
- Weakness
- CWE-200
- Published
- 2022-03-01
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference