CVE-2022-0235
MEDIUMnode-fetch < 2.6.7 and >=3.0.0 <3.1.1 - Open Redirect via URL Validation Bypass
Title source: llmDescription
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
References (4)
Core 4
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html
Patch, Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
Patch, Third Party Advisory
https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10
Exploit, Third Party Advisory
https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7
Scores
CVSS v3
6.1
EPSS
0.0029
EPSS Percentile
52.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
CWE-200
Status
published
Products (5)
debian/debian_linux
10.0
node-fetch_project/node-fetch
< 2.6.7
npm/node-fetch
3.0.0 - 3.1.1npm
siemens/sinec_ins
1.0 (2 CPE variants)
siemens/sinec_ins
< 1.0
Published
Jan 16, 2022
Tracked Since
Feb 18, 2026