got is vulnerable to Exposure of Sensitive Information
39
Low Risk
Got can copy request headers from a piped source stream onto the outgoing request when the copyPipedHeaders option is enabled for proxy-style forwarding. Before the fix, the set of omitted piped headers did not include credential headers, so authorization, cookie, and related headers from an incoming request were forwarded to the target upstream, including across origins. This can disclose a caller's credentials to an unintended or cross-origin server acting as a confused deputy. The fix adds authorization, cookie, cookie2, set-cookie, and set-cookie2 to the omitted piped headers so they are no longer copied automatically.
You are affected if you are using a version that falls within the vulnerable range and you enable copyPipedHeaders to forward headers from an incoming piped request, allowing credential headers such as authorization and cookie to be copied to a different upstream.
got is vulnerable to Exposure of Sensitive Information in versions 14.6.0 - 15.1.0.
Upgrade the got library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.