GHSA-77mv-4rg7-r8qv

    Dashboard / Vulnerabilities / GHSA-77mv-4rg7-r8qv

    GHSA-77mv-4rg7-r8qv

    Published: 17 Jun 2022Last Modified: 8 Nov 2023

    Summary: Potential Sensitive Cookie Exposure in NPM Packages @finastra/nestjs-proxy, @ffdc/nestjs-proxy

    Details: The nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application developer. This could have led to sensitive cookies being inadvertently exposed to such services that should not see them. The patched version now blocks cookies from being forwarded by default. However developers can configure an allow-list of cookie names by using the `allowedCookies` config setting. Further details of this feature can be found in the library's README on [Github](https://github.com/Finastra/finastra-nodejs-libs/tree/develop/libs/proxy) or [NPM](https://www.npmjs.com/package/@finastra/nestjs-proxy). ### Patches - This issue has been fixed in version 0.7.0 of `@finastra/nestjs-proxy`. - Users of `@ffdc/nestjs-proxy` are advised that this package has been deprecated and is no longer being maintained or receiving updates. Please update your package.json file to use `@finastra/nestjs-proxy` instead. ### References - https://github.com/Finastra/finastra-nodejs-libs/pull/232 - https://github.com/Finastra/finastra-nodejs-libs/blob/master/libs/proxy/README.md

    Affected packages

    Package

    Name: @finastra/nestjs-proxy

    Purl: pkg:npm/%40finastra/nestjs-proxy

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.7.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-77mv-4rg7-r8qv | CVE-DB