Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40375
HistoryMay 02, 2023 - 3:54 a.m.

Information Disclosure

2023-05-0203:54:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
typed-rest-client
information disclosure
authentication
redirection
vulnerability
software
attack
authentication data
third parties

0.003 Low

EPSS

Percentile

68.9%

typed-rest-client is vulnerable to Information Disclosure. The vulnerability exists because the library does not disable the authentications on redirections, which allows an attacker to send a malicious request with BasicCredentialHandler, BearerCredentialHandler, or PersonalAccessTokenCredentialHandler, which return the target host with a link to a second host, leading to a leak of authentication data to 3rd parties.

0.003 Low

EPSS

Percentile

68.9%

Related for VERACODE:40375