VDB
Sign up
CRITICAL9.1

GHSA-558p-m34m-vpmq

Potential leak of authentication data to 3rd parties

Quick fix

GHSA-558p-m34m-vpmq — typed-rest-client: upgrade to the fixed version with the command below.

npm install typed-rest-client@1.8.0

Details

### Impact Users of typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties.

The flow of the vulnerability is as follows:

1. Send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler` 2. The target host may return a redirection (3xx), with a link to a second host. 3. The next request will use the credentials to authenticate with the second host, by setting the `Authorization` header.

The expected behavior is that the next request will *NOT* set the `Authorization` header.

### Patches The problem was fixed on April 1st 2020.

### Workarounds There is no workaround.

### References This is similar to the following issues in nature: 1. [HTTP authentication leak in redirects](https://curl.haxx.se/docs/CVE-2018-1000007.html) - I used the same solution as CURL did. 2. [CVE-2018-1000007](https://nvd.nist.gov/vuln/detail/CVE-2018-1000007).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/typed-rest-client
Introduced in: 0Fixed in: 1.8.0
Fixnpm install typed-rest-client@1.8.0

References