CVE-2022-0155: Exposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirects
A flaw was found in follow-redirects when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.
Other sources
follow-redirects could allow a remote attacker to obtain sensitive information, caused by an unauthorized actor. By sending a specially-crafted request, a remote authenticated attacker could exploit this vulnerability to obtain private personal information and use this information to launch further attacks against the affected system.
— IBM
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0155?
CVE-2022-0155 is a vulnerability that allows a remote attacker to obtain sensitive information by sending a specially-crafted request.
How does CVE-2022-0155 affect the follow-redirects package?
CVE-2022-0155 affects the follow-redirects package, allowing a remote attacker to obtain sensitive information.
How can an attacker exploit CVE-2022-0155?
An attacker can exploit CVE-2022-0155 by sending a specially-crafted request to obtain private personal information.
What is the severity of CVE-2022-0155?
CVE-2022-0155 has a severity rating of high.
How can I fix CVE-2022-0155 in the follow-redirects package?
To fix CVE-2022-0155 in the follow-redirects package, update to version 1.14.9 or later.