Vulnerabilities/

Exposure of Sensitive Information in eventsource

Severity:
High

Description

When fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application. According to the same-origin-policy, the header should be “sanitized.

Recommendation

Update the eventsource package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
eventsource
Anything's wrong? Let us know Last updated on November 28, 2023

This issue is available in SmartScanner Professional

See Pricing