CVE-2022-1365: Exposure of Private Personal Information to an Unauthorized Actor in lquixada/cross-fetch
A flaw was found in the cross-fetch library when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.
Other sources
cross-fetch could allow a remote authenticated attacker to obtain sensitive information, caused by a flaw in the Cookie header. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.
— IBM
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-1365?
CVE-2022-1365 has been classified with a high severity rating due to the potential for sensitive cookie information to be leaked.
How do I fix CVE-2022-1365?
To remediate CVE-2022-1365, update the cross-fetch library to version 3.1.5 or later.
Which software is affected by CVE-2022-1365?
CVE-2022-1365 affects the cross-fetch library and IBM Security QRadar EDR versions prior to 3.12.
What is the impact of CVE-2022-1365?
The impact of CVE-2022-1365 allows an authenticated remote attacker to hijack accounts by leaking sensitive cookie information.
Is CVE-2022-1365 a common vulnerability?
CVE-2022-1365 may not be widely recognized but poses significant risks due to its ability to exploit authentication credentials.