Bug 2047262 (CVE-2022-0355) - CVE-2022-0355 simple-get: exposure of sensitive information to an unauthorized actor
Summary: CVE-2022-0355 simple-get: exposure of sensitive information to an unauthorize...
Keywords:
Status: NEW
Alias: CVE-2022-0355
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2048452
Blocks: 2047263
TreeView+ depends on / blocked
 
Reported: 2022-01-27 13:30 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-10-25 17:21 UTC (History)
7 users (show)

Fixed In Version: simple-get 4.0.1
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the simple-get library when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to expose sensitive information from an unauthorized actor as the cookie is leaked.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2022-01-27 13:30:35 UTC
Exposure of Sensitive Information to an Unauthorized Actor in NPM simple-get prior to 4.0.1.

Reference:
https://huntr.dev/bounties/42c79c23-6646-46c4-871d-219c0d4b4e31

Upstream patch:
https://github.com/feross/simple-get/commit/e4af095e06cd69a9235013e8507e220a79b9684f


Note You need to log in before you can comment on or make changes to this bug.