Sensitive information sent insecurely In simple-get
Description
Exposure of Sensitive Information in simple-get In versions of simple-get prior to 4.0.1, 3.1.1, and 2.8.2, when fetching a remote url with a cookie location response, headers will be followed, potentially resulting in an exposure of the session cookie to a third party.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 4.0.1, 3.1.1, 2.8.2 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.