Jimmy Wärting

3 exploits Active since Jan 2022
CVE-2022-21970 NOMISEC MEDIUM WRITEUP
Microsoft Edge < - Privilege Escalation
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
14 stars
CVSS 6.1
CVE-2025-22150 WRITEUP MEDIUM WRITEUP
Undici <5.28.5,6.21.1,7.2.3 - Info Disclosure
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generated values are known. If there is a mechanism in an app that sends multipart requests to an attacker-controlled website, they can use this to leak the necessary values. Therefore, an attacker can tamper with the requests going to the backend APIs if certain conditions are met. This is fixed in versions 5.28.5, 6.21.1, and 7.2.3. As a workaround, do not issue multipart requests to attacker controlled servers.
CVSS 6.8
CVE-2022-0235 WRITEUP MEDIUM WRITEUP
node-fetch < 2.6.7 and >=3.0.0 <3.1.1 - Open Redirect via URL Validation Bypass
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVSS 6.1