Vulnerabilities/

follow-redirects' Proxy-Authorization header kept across hosts

Severity:
Medium

Description

When using axios, its dependency follow-redirects only clears authorization header during cross-domain redirect, but allows the proxy-authentication header which contains credentials too.

Recommendation

Update the follow-redirects package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
follow-redirects
Anything's wrong? Let us know Last updated on April 02, 2024

This issue is available in SmartScanner Professional

See Pricing