Headline
GHSA-3787-6prv-h9w3: Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Impact
Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization
headers.
Patches
This is patched in v5.28.3 and v6.6.1
Workarounds
There are no known workarounds.
References
- https://fetch.spec.whatwg.org/#authentication-entries
- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Low severity GitHub Reviewed Published Feb 16, 2024 in nodejs/undici • Updated Feb 16, 2024