Lucene search

K
osvGoogleOSV:GHSA-6H5X-7C5M-7CR7
HistoryMay 13, 2022 - 12:01 a.m.

Exposure of Sensitive Information in eventsource

2022-05-1300:01:12
Google
osv.dev
139

0.002 Low

EPSS

Percentile

57.7%

When fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application. According to the same-origin-policy, the header should be “sanitized.”