/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-28849

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-28849

Severity

6.5

Medium

CVSS V3

Summary

Proxy-Authorization header kept across hosts in follow-redirects

Description

follow-redirects is an open source, drop-in replacement for Node's http and https modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which contains credentials too. This vulnerability may lead to credentials leak, but has been addressed in version 1.15.6. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing