-
Notifications
You must be signed in to change notification settings - Fork 6.8k
Closed
Labels
priority:contrib-neededHelp/Contributions wanted from community membersHelp/Contributions wanted from community members
Description
Affecting Packages/Plugins
- example-app
- @backstage/catalog-client
- @backstage/errors
- @backstage/integration
- @backstage/test-utils
- @backstage/plugin-apache-airflow
- @backstage/plugin-api-docs
- @backstage/plugin-bitrise
- @backstage/plugin-fossa
- @backstage/plugin-permission-common
- @backstage/plugin-permission-react
- @backstage/plugin-sonarqube
- @backstage/plugin-techdocs-backend
Overview
node-fetch is a light-weight module that brings window.fetch to node.js
Affected versions of this package are vulnerable to Information Exposure when fetching a remote url with Cookie, if it get a Location
response header, it will follow that url and try to fetch that url with provided cookie. This can lead to forwarding secure headers to 3th party.
Remediation
Upgrade node-fetch
to version 2.6.7, 3.1.1 or higher.
References
Metadata
Metadata
Assignees
Labels
priority:contrib-neededHelp/Contributions wanted from community membersHelp/Contributions wanted from community members