Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25139
HistoryApr 30, 2020 - 1:44 a.m.

Information Disclosure

2020-04-3001:44:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.002 Low

EPSS

Percentile

52.1%

@actions/http-client is vulnerable to information disclosure. When a request that results in a 302 redirect contains a Authorization header, the credentials is disclosed to the other domain.

CPENameOperatorVersion
@actions/http-clientle1.0.7

0.002 Low

EPSS

Percentile

52.1%