Executive brief
follow-redirects is a widely-used Node.js library that handles HTTP redirects automatically. A flaw in versions before 1.14.8 allowed sensitive headers (such as authorization tokens or session credentials) to be leaked to unauthorized third-party servers when following HTTP redirects. An attacker controlling a malicious website could trick users into following redirect chains that expose confidential information to attackers' servers.
Technical details
The vulnerability stems from improper header filtering when processing HTTP redirects across different URL schemes (e.g., HTTPS to HTTP). The library failed to drop sensitive headers (such as Authorization and Cookie headers) when following redirects, particularly across scheme boundaries where security downgrade is involved. An attacker can construct a malicious redirect chain that causes client applications using follow-redirects to inadvertently forward confidential credentials to attacker-controlled endpoints. The issue affects all versions prior to 1.14.8, which was patched to properly drop sensitive headers across schemes. The attack requires no authentication and is triggered by network-level HTTP redirect responses.
Affected products
- follow-redirects follow-redirects before 1.14.8
Timeline
- 2022-02-10: disclosed
- 2022-02-10: patched: fixed in version 1.14.8