Undici proxy-authorization header not cleared on cross-origin redirect in fetch [LOW] #171

Closed
opened 2024-02-20 17:40:36 +00:00 by Helpdesk · 0 comments
Member

Package: undici (npm)
Affected versions: <= 5.28.2
Patched version: 5.28.3


Impact

Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization headers.

Patches

This is patched in v5.28.3 and v6.6.1

Workarounds

There are no known workarounds.

References

Package: undici (npm) Affected versions: <= 5.28.2 Patched version: 5.28.3 --- ## Impact Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers. ## Patches This is patched in v5.28.3 and v6.6.1 ## Workarounds There are no known workarounds. ## References - https://fetch.spec.whatwg.org/#authentication-entries - [GHSA-wqq4-5wpv-mx2g](https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g)
Helpdesk added the
type
dependencies
label 2024-02-20 17:40:39 +00:00
Helpdesk added this to the 0.5.1 milestone 2024-02-20 17:40:41 +00:00
Vylpes self-assigned this 2024-03-14 17:32:14 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: External/card-drop#171
No description provided.