Junglewise Threat Intelligence

CVE-2024-28849: follow-redirects Proxy-Authorization header disclosure in cross-domain redirects

CVE-2024-28849 · Severity: low · CVSS 3.1 · Published 2024-03-14

Technologies: Follow-Redirects. Vendors: npm.

Executive brief

follow-redirects is a popular Node.js library used by axios and other HTTP clients to transparently handle HTTP redirects. The library fails to remove the Proxy-Authorization header (which contains credentials for authenticating to proxy servers) when requests are redirected across different domains, unlike how it properly clears regular Authorization and Cookie headers. An attacker controlling a target domain could receive proxy credentials intended for a different host, potentially compromising proxy infrastructure security.

Technical details

The vulnerability is an information disclosure flaw in follow-redirects' cross-domain redirect handling. The library's removeMatchingHeaders() function removes Authorization and Cookie headers during cross-domain redirects (per RFC 7231 and Fetch spec), but does not include Proxy-Authorization in the clearance regex. This allows proxy credentials to leak to destination hosts during redirects. The attack requires a cross-domain redirect to occur (which can be triggered by a legitimate HTTP 3xx response from the initial server), and the attacker must control the redirect target host. The fix adds "proxy-authorization" to the headers cleared during cross-domain redirects and was released in version 1.15.6.

Affected products

  • follow-redirects follow-redirects < 1.15.6

Timeline

  • 2024-03-14: disclosed
  • 2024-03-14: patched: Fixed in version 1.15.6

References

Related threats