CVE-2022-0536
published 2022-02-09CVE-2022-0536: Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
PriorityP428medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.26%
66.6th percentile
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-follow-redirects | < node-follow-redirects 1.14.8+~1.14.0-1 (bookworm) | node-follow-redirects 1.14.8+~1.14.0-1 (bookworm) |
| follow-redirects | follow-redirects_follow-redirects | >= unspecified < 1.14.8 | 1.14.8 |
| follow-redirects_project | follow-redirects | < 1.14.8 | 1.14.8 |
| follow-redirects_project | follow-redirects | >= 0 < 1.14.8 | 1.14.8 |
| ubuntu | node-follow-redirects | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
follow-redirects vulnerabilities
vendor_ubuntu·2026-04-28·CVSS 6.5
CVE-2024-28849 [MEDIUM] follow-redirects vulnerabilities
Title: follow-redirects vulnerabilities
Summary: Several security issues were fixed in follow-redirects.
It was discovered that follow-redirects did not properly protect sensitive
user information during redirects. An attacker could possibly use this
issue to expose sensitive information. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0155)
It was discovered that follow-redirects did not properly remove sensitive
information before storage or transfer. An attacker could possibly use this
issue to expose sensitive information. This issue only affected Ubuntu
18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0536)
It was discovered that follow-redirects did not properly validate URLs when
handling certain inputs. An attacker could possibly use this issue to
redirect us
Red Hat
follow-redirects: Exposure of Sensitive Information via Authorization Header leak
vendor_redhat·2022-02-09·CVSS 2.6
CVE-2022-0536 [LOW] CWE-319 follow-redirects: Exposure of Sensitive Information via Authorization Header leak
follow-redirects: Exposure of Sensitive Information via Authorization Header leak
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
A flaw was found in the follow-redirects package. This flaw allows the exposure of sensitive information to an unauthorized actor due to the usage of insecure HTTP protocol. This issue happens with an Authorization header leak from the same hostname, https-http, and requires a Man-in-the-Middle (MITM) attack.
Package: migration-toolkit-virtualization/mtv-ui-rhel8 (Migration Toolkit for Virtualization) - Will not fix
Package: rh-dotnet31-dotnet (.NET Core 3.1 on Red Hat Enterprise Linux) - Out of support scope
Package: odo (OpenShift Developer Tools and Services) - Will not fix
Package: kiali (Op
Debian
CVE-2022-0536: node-follow-redirects - Improper Removal of Sensitive Information Before Storage or Transfer in NPM foll...
vendor_debian·2022·CVSS 2.6
CVE-2022-0536 [LOW] CVE-2022-0536: node-follow-redirects - Improper Removal of Sensitive Information Before Storage or Transfer in NPM foll...
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
Scope: local
bookworm: resolved (fixed in 1.14.8+~1.14.0-1)
bullseye: resolved (fixed in 1.13.1-1+deb11u1)
forky: resolved (fixed in 1.14.8+~1.14.0-1)
sid: resolved (fixed in 1.14.8+~1.14.0-1)
trixie: resolved (fixed in 1.14.8+~1.14.0-1)
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
ghsa·2022-02-10
CVE-2022-0536 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
osv·2022-02-10
CVE-2022-0536 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.
OSV
CVE-2022-0536: Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1
osv·2022-02-09·CVSS 5.9
CVE-2022-0536 [MEDIUM] CVE-2022-0536: Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445https://huntr.dev/bounties/7cf2bf90-52da-4d59-8028-a73b132de0dbhttps://github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445https://huntr.dev/bounties/7cf2bf90-52da-4d59-8028-a73b132de0db
2022-02-09
Published