icon

We found results for “

CVE-2023-30846

Good to know:

icon

Date: April 26, 2023

typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with "BasicCredentialHandler", "BearerCredentialHandler" or "PersonalAccessTokenCredentialHandler". Second, the target host may return a redirection (3xx), with a link to a second host. Third, the next request will use the credentials to authenticate with the second host, by setting the "Authorization" header. The expected behavior is that the next request will NOT set the "Authorization" header. The problem was fixed in version 1.8.0. There are no known workarounds.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Insufficiently Protected Credentials

CWE-522

Top Fix

icon

Upgrade Version

Upgrade to version typed-rest-client - 1.8.0

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us