{"id":"GHSA-x565-32qp-m3vf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x565-32qp-m3vf","summary":"phin may include sensitive headers in subsequent requests after redirect","details":"### Impact\n\nUsers may be impacted if sending requests including sensitive data in specific headers with `followRedirects` enabled.\n\n### Patches\n\nThe [follow-redirects](https://github.com/follow-redirects/follow-redirects) library is now being used for redirects and removes some headers that may contain sensitive information in some situations.\n\n### Workarounds\n\nN/A. Please update to resolve the issue.","published":"2024-04-11T21:30:30Z","modified":"2024-04-11T21:30:31Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"phin","fixedVersion":"3.7.1"}],"fix":{"url":"https://github.com/ethanent/phin/commit/c071f95336a987dad9332fd388adeb249925cc57","label":"ethanent/phin@c071f95"},"references":[{"type":"WEB","url":"https://github.com/ethanent/phin/security/advisories/GHSA-x565-32qp-m3vf"},{"type":"WEB","url":"https://github.com/ethanent/phin/commit/c071f95336a987dad9332fd388adeb249925cc57"},{"type":"PACKAGE","url":"https://github.com/ethanent/phin"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-04-11T21:30:31Z"}}