Follow-Redirects Project Follow-Redirects vulnerabilities

4 known vulnerabilities affecting follow-redirects_project/follow-redirects.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2024-28849MEDIUMCVSS 6.5fixed in 1.15.62024-03-14
CVE-2024-28849 [MEDIUM] CWE-200 CVE-2024-28849: follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that a follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials le
ghsanvdosv
CVE-2023-26159HIGHCVSS 7.3fixed in 1.15.42024-01-02
CVE-2023-26159 [HIGH] CWE-20 CVE-2023-26159: Versions of the package follow-redirects before 1 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other s
cvelistv5ghsaosv
CVE-2022-0536MEDIUMCVSS 5.9fixed in 1.14.82022-02-09
CVE-2022-0536 [MEDIUM] CWE-212 CVE-2022-0536: Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior t Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
ghsanvdosv
CVE-2022-0155MEDIUMCVSS 6.5fixed in 1.14.72022-01-10
CVE-2022-0155 [MEDIUM] CWE-359 CVE-2022-0155: follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
ghsanvdosv