Executive brief
requestretry is a Node.js library used by developers to add automatic retry logic to HTTP requests. The library inadvertently forwards authentication cookies and authorization headers when requests are redirected to external domains, leaking sensitive credentials to untrusted sites. An attacker controlling a redirect target could harvest these credentials, potentially gaining unauthorized access to user accounts or services.
Technical details
The vulnerability is an information exposure flaw (CWE-200) in requestretry versions prior to 7.0.0. The root cause is insufficient validation of redirect targets: when an HTTP request is redirected to a different domain, the library continues to forward cookies and Authorization headers without checking whether the redirect target is a trusted domain. This allows cookies and credentials intended for the original domain to be leaked to external sites. No authentication or special network access is required; any application using requestretry to make HTTP requests through redirects is vulnerable. An attacker can exploit this by controlling a redirect target to harvest credentials. The fix, available in version 7.0.0, strips cookies and authorization headers before following cross-domain redirects.
Affected products
- requestretry requestretry prior to 7.0.0
Timeline
- 2022-02-24: disclosed
- 2022: patched: Fixed in version 7.0.0