Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Description
Published to the GitHub Advisory Database
Feb 16, 2024
Reviewed
Feb 16, 2024
Published by the National Vulnerability Database
Feb 16, 2024
Last updated
May 2, 2024
Impact
Undici already cleared Authorization headers on cross-origin redirects, but did not clear
Proxy-Authorization
headers.Patches
This is patched in v5.28.3 and v6.6.1
Workarounds
There are no known workarounds.
References
References