PT-2022-16827 · Unknown · Fluture-Node

Avaq

·

Published

2022-03-01

·

Updated

2023-07-03

·

CVE-2022-24719

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fluture-Node versions 4.0.0 through 4.0.1
Description Using followRedirects or followRedirectsWith with any of the redirection strategies built into Fluture-Node, paired with a request that includes confidential headers such as Authorization or Cookie, exposes you to a vulnerability where, if the destination server were to redirect the request to a server on a third-party domain, or the same domain over unencrypted HTTP, the headers would be included in the follow-up request and be exposed to the third party, or potential http traffic sniffing.
Recommendations For versions 4.0.0 and 4.0.1, use a custom redirection strategy via the followRedirectsWith function as a temporary workaround, based on the new strategies available in Fluture-Node@4.0.2. Update to version 4.0.2, which automatically redacts confidential headers when a redirect is followed across to another origin.

Exploit

Fix

Open Redirect

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-24719
GHSA-32X6-QVW6-MXJ4
PYSEC-2022-43051
PYSEC-2022-43052

Affected Products

Fluture-Node