First published: Fri Apr 15 2022(Updated: )
A flaw was found in the cross-fetch library when fetching a remote URL with a cookie when it gets to the Location response header. This flaw allows an attacker to hijack the account as the cookie is leaked.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cross-fetch | <3.1.5 | 3.1.5 |
Cross-fetch | <3.1.5 | |
IBM Security QRadar | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1365 has been classified with a high severity rating due to the potential for sensitive cookie information to be leaked.
To remediate CVE-2022-1365, update the cross-fetch library to version 3.1.5 or later.
CVE-2022-1365 affects the cross-fetch library and IBM Security QRadar EDR versions prior to 3.12.
The impact of CVE-2022-1365 allows an authenticated remote attacker to hijack accounts by leaking sensitive cookie information.
CVE-2022-1365 may not be widely recognized but poses significant risks due to its ability to exploit authentication credentials.