Junglewise Threat Intelligence

CVE-2022-1365: cross-fetch authorization bypass via HTTP redirect

CVE-2022-1365 · Severity: low · CVSS 3.1 · Published 2022-04-17

Executive brief

cross-fetch is a lightweight HTTP client library used in Node.js applications to make web requests. When fetching a remote URL with authentication cookies, if the server responds with an HTTP redirect (Location header), the library incorrectly forwards the original cookies to the redirected destination. An attacker controlling a redirect target could capture authentication credentials intended for the original site.

Technical details

The vulnerability is an incorrect authorization flaw in cross-fetch's HTTP redirect handling. When a fetch request includes authentication cookies and the server responds with a Location header (HTTP redirect), the library follows the redirect and includes the original cookies in the request to the redirect target, violating proper cookie scope restrictions. An attacker can exploit this by controlling a server that issues redirects to attacker-controlled domains, causing credentials to leak. The vulnerability affects versions prior to 2.2.6 and 3.1.5. Patches are available in the referenced pull request and commits.

Affected products

  • cross-fetch cross-fetch before 2.2.6 and before 3.1.5

Timeline

  • 2022-04-15: disclosed
  • 2022-04-17: advisory
  • 2022-04-10: patched
  • 2025-10-08: other: Advisory withdrawn

References