{"id":"GHSA-wpg7-2c88-r8xv","summary":"Exposure of Sensitive Information in simple-get","details":"In versions of simple-get prior to 4.0.1, 3.1.1, and 2.8.2, when fetching a remote url with a cookie location response, headers will be followed, potentially resulting in an exposure of the session cookie to a third party.","aliases":["CVE-2022-0355"],"modified":"2026-09-10T03:49:11.488315452Z","published":"2022-01-28T22:54:16Z","database_specific":{"github_reviewed_at":"2022-01-27T23:17:09Z","nvd_published_at":"2022-01-26T04:15:00Z","cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0355"},{"type":"WEB","url":"https://github.com/feross/simple-get/pull/75#issuecomment-1027755026"},{"type":"WEB","url":"https://github.com/feross/simple-get/pull/76#issuecomment-1027754710"},{"type":"WEB","url":"https://github.com/feross/simple-get/commit/e4af095e06cd69a9235013e8507e220a79b9684f"},{"type":"WEB","url":"https://github.com/feross/simple-get"},{"type":"WEB","url":"https://huntr.dev/bounties/42c79c23-6646-46c4-871d-219c0d4b4e31"}],"affected":[{"package":{"name":"simple-get","ecosystem":"npm","purl":"pkg:npm/simple-get"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.0.1"}]}],"versions":["4.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wpg7-2c88-r8xv/GHSA-wpg7-2c88-r8xv.json"}},{"package":{"name":"simple-get","ecosystem":"npm","purl":"pkg:npm/simple-get"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wpg7-2c88-r8xv/GHSA-wpg7-2c88-r8xv.json"}},{"package":{"name":"simple-get","ecosystem":"npm","purl":"pkg:npm/simple-get"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.8.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-wpg7-2c88-r8xv/GHSA-wpg7-2c88-r8xv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}