{"id":"GHSA-7gc6-qh9x-w6h8","summary":"Withdrawn Advisory: Incorrect Authorization in cross-fetch","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the vulnerability originates from a dependency. For more information, see the `Maintainer` comments in https://huntr.com/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac.\n\n## Original Description\nWhen fetching a remote url with Cookie if it get Location response header then it will follow that url and try to fetch that url with provided cookie . So cookie is leaked here to thirdparty.\nEx: you try to fetch example.com with cookie and if it get redirect url to attacker.com then it fetch that redirect url with provided cookie .","aliases":["CVE-2022-1365"],"modified":"2026-09-10T03:49:18.836642303Z","published":"2022-04-17T00:00:32Z","withdrawn":"2025-10-08T19:22:14Z","database_specific":{"cwe_ids":["CWE-359","CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-28T20:45:25Z","nvd_published_at":"2022-04-15T23:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1365"},{"type":"WEB","url":"https://github.com/lquixada/cross-fetch/pull/135"},{"type":"WEB","url":"https://github.com/lquixada/cross-fetch/commit/a3b3a9481091ddd06b8f83784ba9c4e034dc912a"},{"type":"PACKAGE","url":"https://github.com/lquixada/cross-fetch"},{"type":"WEB","url":"https://huntr.dev/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac"}],"affected":[{"package":{"name":"cross-fetch","ecosystem":"npm","purl":"pkg:npm/cross-fetch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.1.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-7gc6-qh9x-w6h8/GHSA-7gc6-qh9x-w6h8.json"}},{"package":{"name":"cross-fetch","ecosystem":"npm","purl":"pkg:npm/cross-fetch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-7gc6-qh9x-w6h8/GHSA-7gc6-qh9x-w6h8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}