Vulnerabilities/

node-fetch forwards secure headers to untrusted sites

Severity:
High

Description

node-fetch forwards secure headers such as authorization, www-authenticate, cookie, & cookie2 when redirecting to a untrusted site.

Recommendation

Update the node-fetch package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
node-fetch
Anything's wrong? Let us know Last updated on November 29, 2023

This issue is available in SmartScanner Professional

See Pricing