GHSA-7gc6-qh9x-w6h8
Dashboard / Vulnerabilities / GHSA-7gc6-qh9x-w6h8
Summary: Withdrawn Advisory: Incorrect Authorization in cross-fetch
Details: ## Withdrawn Advisory This advisory has been withdrawn because the vulnerability originates from a dependency. For more information, see the `Maintainer` comments in https://huntr.com/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac. ## Original Description When fetching a remote url with Cookie if it get Location response header then it will follow that url and try to fetch that url with provided cookie . So cookie is leaked here to thirdparty. Ex: you try to fetch example.com with cookie and if it get redirect url to attacker.com then it fetch that redirect url with provided cookie .
References: https://nvd.nist.gov/vuln/detail/CVE-2022-1365, https://github.com/lquixada/cross-fetch/pull/135, https://github.com/lquixada/cross-fetch/commit/a3b3a9481091ddd06b8f83784ba9c4e034dc912a, https://github.com/lquixada/cross-fetch, https://huntr.dev/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac
Affected packages
Package
Name: cross-fetch
Purl: pkg:npm/cross-fetch
Affected ranges
Type: SEMVER
Events:
