Information Exposure Affecting fluture-node package, versions >=4.0.0 <4.0.2
Threat Intelligence
EPSS
0.12% (48th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-FLUTURENODE-2414101
- published 2 Mar 2022
- disclosed 2 Mar 2022
- credit Unknown
Introduced: 2 Mar 2022
CVE-2022-24719 Open this link in a new tabHow to fix?
Upgrade fluture-node
to version 4.0.2 or higher.
Overview
fluture-node is a FP-style HTTP and streaming utils for Node based on Fluture
Affected versions of this package are vulnerable to Information Exposure. Using followRedirects
or followRedirectsWith
with any of the redirection strategies paired with a request that includes confidential headers such as Authorization
or Cookie
may lead to this information leaking to a third party.
References
CVSS Scores
version 3.1