Executive brief
simple-get is a lightweight HTTP request library used by Node.js applications. When handling redirects (HTTP 3xx responses), the library fails to strip session cookies before following the redirect, potentially exposing sensitive authentication tokens to unintended third-party servers. An attacker who can control a redirect target can steal session cookies from applications using vulnerable versions.
Technical details
This is an information disclosure vulnerability (CWE-200) in the redirect-handling logic of simple-get. When the library follows HTTP Location headers in response to requests with cookies, it fails to validate that the redirect target is the same origin before forwarding the Set-Cookie headers and session data. The vulnerability is exploitable remotely without authentication or user interaction, affecting versions 4.0.0, 3.0.0–3.1.0, and all versions prior to 2.8.2. Patches were released as simple-get 4.0.1, 3.1.1, and 2.8.2, which properly prevent cookie leakage across redirect boundaries.
Affected products
- simple-get simple-get before 2.8.2, 3.0.0 to 3.1.0, 4.0.0
Timeline
- 2022-01-28: disclosed
- 2022-01: patched: versions 4.0.1, 3.1.1, and 2.8.2 released