Lucene search

K
osvGoogleOSV:GHSA-WPG7-2C88-R8XV
HistoryJan 28, 2022 - 10:54 p.m.

Exposure of Sensitive Information in simple-get

2022-01-2822:54:16
Google
osv.dev
40

0.002 Low

EPSS

Percentile

54.1%

In versions of simple-get prior to 4.0.1, 3.1.1, and 2.8.2, when fetching a remote url with a cookie location response, headers will be followed, potentially resulting in an exposure of the session cookie to a third party.

0.002 Low

EPSS

Percentile

54.1%