Skip to content

Sensitive headers may be included in subsequent requests after redirect

Moderate
ethanent published GHSA-x565-32qp-m3vf Apr 11, 2024

Package

npm phin (npm)

Affected versions

<3.7.1

Patched versions

3.7.1

Description

Impact

Users may be impacted if sending requests including sensitive data in specific headers with followRedirects enabled.

Patches

The follow-redirects library is now being used for redirects and removes some headers that may contain sensitive information in some situations.

Workarounds

N/A. Please update to resolve the issue.

Credit

Please let me know if you were the one who originally discovered the issue so you can be credited here!

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs