Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Snyk vulnerability [SNYK-JS-NODEFETCH-2342118] #8985

@github-actions

Description

@github-actions

Affecting Packages/Plugins

Overview

node-fetch is a light-weight module that brings window.fetch to node.js

Affected versions of this package are vulnerable to Information Exposure when fetching a remote url with Cookie, if it get a Location response header, it will follow that url and try to fetch that url with provided cookie. This can lead to forwarding secure headers to 3th party.

Remediation

Upgrade node-fetch to version 2.6.7, 3.1.1 or higher.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority:contrib-neededHelp/Contributions wanted from community members

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions