This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Http-Client Project First view 2020-04-29
Product Http-Client Last view 2020-04-29
Version Type Application
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:http-client_project:http-client:*:*:*:*:*:node.js:*:* 1

Related : CVE

  Date Alert Description
7.5 2020-04-29 CVE-2020-11021

Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect (302) and 3. the redirect url redirects to another domain or hostname Then the authorization header will get passed to the other domain. The problem is fixed in version 1.0.8.