node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7 | third party advisory exploit |
https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10 | third party advisory patch |
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html | third party advisory mailing list |