CVE-2022-0536 (Low) detected in follow-redirects-1.14.7.tgz #1238
Labels
cve
Security vulnerabilities detected by Dependabot or Mend
low severity
Low severity CVE
Mend: dependency security vulnerability
Security vulnerability detected by Mend
v2.0.0
CVE-2022-0536 - Low Severity Vulnerability
Vulnerable Library - follow-redirects-1.14.7.tgz
HTTP and HTTPS modules that follow redirects.
Library home page: https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.14.7.tgz
Dependency Hierarchy:
Found in HEAD commit: f981b395344845e11576612d79b0605424b6b31d
Found in base branch: main
Vulnerability Details
Exposure of Sensitive Information to an Unauthorized Actor in NPM follow-redirects prior to 1.14.8.
Publish Date: 2022-02-09
URL: CVE-2022-0536
CVSS 3 Score Details (2.6)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0536
Release Date: 2022-02-09
Fix Resolution: follow-redirects - 1.14.8
The text was updated successfully, but these errors were encountered: