VDB
Sign up
HIGH8.8

GHSA-r683-j2x4-v87g

node-fetch forwards secure headers to untrusted sites

Quick fix

GHSA-r683-j2x4-v87g — node-fetch: upgrade to the fixed version with the command below.

npm install node-fetch@3.1.1

Details

node-fetch forwards secure headers such as `authorization`, `www-authenticate`, `cookie`, & `cookie2` when redirecting to a untrusted site.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-fetch
Introduced in: 3.0.0Fixed in: 3.1.1
Fixnpm install node-fetch@3.1.1
npm/node-fetch
Introduced in: 0Fixed in: 2.6.7
Fixnpm install node-fetch@2.6.7

References