Linuxsecurity
Credential Disclosure Risk in Node.js Module Follow-Redirects
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vulnerability was discovered in the Node.js module 'follow-redirects' that fails to remove custom authentication headers during cross-domain redirects. This flaw, identified by Dennis Sepede, could allow attackers to obtain sensitive authentication information, leading to credential disclosure. The affected versions include node-follow-redirects 1.15.11 for Ubuntu 26.04 LTS and earlier versions for Ubuntu 24.04, 22.04, 20.04, and 18.04 LTS. Users are advised to update their systems to mitigate this risk. The vulnerability impacts systems using the affected versions of the module, particularly those handling sensitive authentication data. A standard system update is recommended to apply the necessary patches. The issue has been documented in Ubuntu Security Notice USN-8632-1.
Key Points: • A vulnerability in 'follow-redirects' can lead to credential disclosure. • The flaw affects multiple Ubuntu LTS versions, requiring urgent updates. • Users should perform standard system updates to mitigate the risk.