CVE-2022-0155
published 2022-01-10CVE-2022-0155: follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
2.43%
82.5th percentile
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-follow-redirects | < node-follow-redirects 1.14.7+~1.13.1-1 (bookworm) | node-follow-redirects 1.14.7+~1.13.1-1 (bookworm) |
| follow-redirects | follow-redirects_follow-redirects | >= unspecified < 1.14.7 | 1.14.7 |
| follow-redirects_project | follow-redirects | < 1.14.7 | 1.14.7 |
| follow-redirects_project | follow-redirects | >= 0 < 1.14.7 | 1.14.7 |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
| ubuntu | node-follow-redirects | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
cisa8.6HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
follow-redirects vulnerabilities
vendor_ubuntu·2026-04-28·CVSS 6.5
CVE-2024-28849 [MEDIUM] follow-redirects vulnerabilities
Title: follow-redirects vulnerabilities
Summary: Several security issues were fixed in follow-redirects.
It was discovered that follow-redirects did not properly protect sensitive
user information during redirects. An attacker could possibly use this
issue to expose sensitive information. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0155)
It was discovered that follow-redirects did not properly remove sensitive
information before storage or transfer. An attacker could possibly use this
issue to expose sensitive information. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0536)
It was discovered that follow-redirects did not properly validate URLs when
handling certain inputs. An attacker could possibly use this issue to
redirect us
CISA ICS
Siemens SINEC INS
cisa_ics·2022-09-15·CVSS 7.8
[HIGH] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedSeptember 15, 2022
Alert CodeICSA-22-258-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Input Validation, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Command Injection, Inadequate Encryption Strength, Missing Encryption of Sensitive Data, Improper Restriction of Operations Within the Bounds of a Memory Buffer, Exposure of Private Personal Information to an Unauthorized Actor, Open Redirect, Improper Resour
CISA
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
cisa·2022-03-03·CVSS 8.6
CVE-2018-0155 [HIGH] CWE-388 Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
Vulnerability: Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability
Affected: Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-0155
Remediation Due Date: 2022-03-17
Red Hat
follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
vendor_redhat·2022-01-10·CVSS 6.5
CVE-2022-0155 [MEDIUM] CWE-359 follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
A flaw was found in follow-redirects when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.
Package: npm-follow-redirects (OpenShift Service Mesh 1) - Out of support scope
Package: npm-follow-redirects (OpenShift Service Mesh 2.0) - Affected
Package: rhacm2/application-ui-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhacm2/console-header-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Will not fix
Package: rhacm2/console-rhel8 (Red Hat Advanced C
Debian
CVE-2022-0155: node-follow-redirects - follow-redirects is vulnerable to Exposure of Private Personal Information to an...
vendor_debian·2022·CVSS 6.5
CVE-2022-0155 [MEDIUM] CVE-2022-0155: node-follow-redirects - follow-redirects is vulnerable to Exposure of Private Personal Information to an...
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Scope: local
bookworm: resolved (fixed in 1.14.7+~1.13.1-1)
bullseye: resolved (fixed in 1.13.1-1+deb11u1)
forky: resolved (fixed in 1.14.7+~1.13.1-1)
sid: resolved (fixed in 1.14.7+~1.13.1-1)
trixie: resolved (fixed in 1.14.7+~1.13.1-1)
OSV
Exposure of sensitive information in follow-redirects
osv·2022-01-12
CVE-2022-0155 [HIGH] Exposure of sensitive information in follow-redirects
Exposure of sensitive information in follow-redirects
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
GHSA
Exposure of sensitive information in follow-redirects
ghsa·2022-01-12
CVE-2022-0155 [HIGH] CWE-359 Exposure of sensitive information in follow-redirects
Exposure of sensitive information in follow-redirects
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
OSV
CVE-2022-0155: follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
osv·2022-01-10·CVSS 6.5
CVE-2022-0155 [MEDIUM] CVE-2022-0155: follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22https://huntr.dev/bounties/fc524e4b-ebb6-427d-ab67-a64181020406https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/follow-redirects/follow-redirects/commit/8b347cbcef7c7b72a6e9be20f5710c17d6163c22https://huntr.dev/bounties/fc524e4b-ebb6-427d-ab67-a64181020406
2022-01-10
Published