CVE-2022-0235Sensitive Information Exposure in Node-fetch

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16
Latest updateJun 13

Description

node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

NVDnode-fetch_project/node-fetch3.0.03.1.1+1
npmnode-fetch_project/node-fetch3.0.03.1.1+1
CVEListV5node-fetch/node-fetch_node-fetchunspecified3.1.1
Debiannode-fetch_project/node-fetch< 2.6.1-5+deb11u1+3
NVDsiemens/sinec_ins< 1.0+1

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

4
OSV
node-fetch forwards secure headers to untrusted sites2022-01-21
GHSA
node-fetch forwards secure headers to untrusted sites2022-01-21
CVEList
Exposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetch2022-01-16
OSV
CVE-2022-0235: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor2022-01-16

📋Vendor Advisories

3
Ubuntu
Node Fetch vulnerability2023-06-13
Red Hat
node-fetch: exposure of sensitive information to an unauthorized actor2022-01-14
Debian
CVE-2022-0235: node-fetch - node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized...2022
CVE-2022-0235 — Sensitive Information Exposure | cvebase