Executive brief
follow-redirects is a popular Node.js library used by axios and other HTTP clients to transparently handle HTTP redirects. The library fails to remove the Proxy-Authorization header (which contains credentials for authenticating to proxy servers) when requests are redirected across different domains, unlike how it properly clears regular Authorization and Cookie headers. An attacker controlling a target domain could receive proxy credentials intended for a different host, potentially compromising proxy infrastructure security.
Technical details
The vulnerability is an information disclosure flaw in follow-redirects' cross-domain redirect handling. The library's removeMatchingHeaders() function removes Authorization and Cookie headers during cross-domain redirects (per RFC 7231 and Fetch spec), but does not include Proxy-Authorization in the clearance regex. This allows proxy credentials to leak to destination hosts during redirects. The attack requires a cross-domain redirect to occur (which can be triggered by a legitimate HTTP 3xx response from the initial server), and the attacker must control the redirect target host. The fix adds "proxy-authorization" to the headers cleared during cross-domain redirects and was released in version 1.15.6.
Affected products
- follow-redirects follow-redirects < 1.15.6
Timeline
- 2024-03-14: disclosed
- 2024-03-14: patched: Fixed in version 1.15.6