CVE-2022-0235
published 2022-01-16CVE-2022-0235: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.65%
74.0th percentile
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-fetch | < node-fetch 2.6.1-7 (bookworm) | node-fetch 2.6.1-7 (bookworm) |
| node-fetch | node-fetch_node-fetch | >= unspecified < 3.1.1 | 3.1.1 |
| node-fetch_project | node-fetch | < 2.6.7 | 2.6.7 |
| node-fetch_project | node-fetch | >= 0 < 2.6.1-5+deb11u1 | 2.6.1-5+deb11u1 |
| node-fetch_project | node-fetch | >= 0 < 2.6.1-7 | 2.6.1-7 |
| node-fetch_project | node-fetch | >= 0 < 2.6.1-7 | 2.6.1-7 |
| node-fetch_project | node-fetch | >= 0 < 2.6.1-7 | 2.6.1-7 |
| node-fetch_project | node-fetch | >= 0 < 2.6.7 | 2.6.7 |
| node-fetch_project | node-fetch | >= 3.0.0 < 3.1.1 | 3.1.1 |
| node-fetch_project | node-fetch | >= 3.0.0 < 3.1.1 | 3.1.1 |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Node Fetch vulnerability
vendor_ubuntu·2023-06-13
CVE-2022-0235 Node Fetch vulnerability
Title: Node Fetch vulnerability
Summary: Node Fetch could be made to expose sensitive information if it opened a
specially crafted file.
It was discovered that Node Fetch incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC INS
cisa_ics·2022-09-15·CVSS 7.8
[HIGH] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedSeptember 15, 2022
Alert CodeICSA-22-258-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: Improper Input Validation, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, Command Injection, Inadequate Encryption Strength, Missing Encryption of Sensitive Data, Improper Restriction of Operations Within the Bounds of a Memory Buffer, Exposure of Private Personal Information to an Unauthorized Actor, Open Redirect, Improper Resour
Red Hat
node-fetch: exposure of sensitive information to an unauthorized actor
vendor_redhat·2022-01-14·CVSS 6.1
CVE-2022-0235 [MEDIUM] CWE-601 node-fetch: exposure of sensitive information to an unauthorized actor
node-fetch: exposure of sensitive information to an unauthorized actor
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
A flaw was found in node-fetch. When following a redirect to a third-party domain, node-fetch was forwarding sensitive headers such as "Authorization," "WWW-Authenticate," and "Cookie" to potentially untrusted targets. This flaw leads to the exposure of sensitive information to an unauthorized actor.
Statement: This flaw is out of support scope for dotnet-5.0. For more information about Dotnet product support scope, please see https://access.redhat.com/support/policy/updates/net-core
Package: distributed-tracing/jaeger-all-in-one-rhel8 (Distributed Tracing Jaeger 1) - Not affected
Package: distributed-tracing/jaeger-query-rhel8 (
Debian
CVE-2022-0235: node-fetch - node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized...
vendor_debian·2022·CVSS 6.1
CVE-2022-0235 [MEDIUM] CVE-2022-0235: node-fetch - node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized...
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Scope: local
bookworm: resolved (fixed in 2.6.1-7)
bullseye: resolved (fixed in 2.6.1-5+deb11u1)
forky: resolved (fixed in 2.6.1-7)
sid: resolved (fixed in 2.6.1-7)
trixie: resolved (fixed in 2.6.1-7)
OSV
node-fetch forwards secure headers to untrusted sites
osv·2022-01-21
CVE-2022-0235 [HIGH] node-fetch forwards secure headers to untrusted sites
node-fetch forwards secure headers to untrusted sites
node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, & `cookie2` when redirecting to a untrusted site.
GHSA
node-fetch forwards secure headers to untrusted sites
ghsa·2022-01-21
CVE-2022-0235 [HIGH] CWE-173 node-fetch forwards secure headers to untrusted sites
node-fetch forwards secure headers to untrusted sites
node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, & `cookie2` when redirecting to a untrusted site.
OSV
CVE-2022-0235: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
osv·2022-01-16·CVSS 6.1
CVE-2022-0235 [MEDIUM] CVE-2022-0235: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7https://lists.debian.org/debian-lts-announce/2022/12/msg00007.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdfhttps://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html
2022-01-16
Published