GHSA-558p-m34m-vpmq
Potential leak of authentication data to 3rd parties
Quick fix
GHSA-558p-m34m-vpmq — typed-rest-client: upgrade to the fixed version with the command below.
npm install typed-rest-client@1.8.0Details
### Impact Users of typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties.
The flow of the vulnerability is as follows:
1. Send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler` 2. The target host may return a redirection (3xx), with a link to a second host. 3. The next request will use the credentials to authenticate with the second host, by setting the `Authorization` header.
The expected behavior is that the next request will *NOT* set the `Authorization` header.
### Patches The problem was fixed on April 1st 2020.
### Workarounds There is no workaround.
### References This is similar to the following issues in nature: 1. [HTTP authentication leak in redirects](https://curl.haxx.se/docs/CVE-2018-1000007.html) - I used the same solution as CURL did. 2. [CVE-2018-1000007](https://nvd.nist.gov/vuln/detail/CVE-2018-1000007).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/microsoft/typed-rest-client/security/advisories/GHSA-558p-m34m-vpmq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-30846[ADVISORY]
- https://github.com/microsoft/typed-rest-client/pull/207[WEB]
- https://github.com/microsoft/typed-rest-client/commit/f9ff755631b982ee1303dfc3e3c823d0d31233e8[WEB]
- https://github.com/microsoft/typed-rest-client[PACKAGE]
- https://security.netapp.com/advisory/ntap-20230601-0008[WEB]