VDB
KO
MEDIUM 5.9

GHSA-pw2r-vq6v-hr8c

Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects

Quick fix

GHSA-pw2r-vq6v-hr8c — follow-redirects: upgrade to the fixed version with the command below.

npm install follow-redirects@1.14.8

Details

Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / follow-redirects
Introduced in: 0 Fixed in: 1.14.8
Fix npm install follow-redirects@1.14.8

References