CVE-2022-0155Exposure of Private Personal Information to an Unauthorized Actor in Follow-redirects

Severity
6.5MEDIUMNVD
CISA8.6
EPSS
1.3%
top 20.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMar 3

Description

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

4
OSV
Exposure of sensitive information in follow-redirects2022-01-12
GHSA
Exposure of sensitive information in follow-redirects2022-01-12
CVEList
Exposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirects2022-01-10
OSV
CVE-2022-0155: follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor2022-01-10

📋Vendor Advisories

3
CISA
Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability2022-03-03
Red Hat
follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor2022-01-10
Debian
CVE-2022-0155: node-follow-redirects - follow-redirects is vulnerable to Exposure of Private Personal Information to an...2022
CVE-2022-0155 — Follow-redirects vulnerability | cvebase