USN-8217-1

Published: 28 Apr 2026, 13:57
Last modified:29 Apr 2026, 10:45

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Apr 2026, 13:57
Published
Vulnerability first disclosed
29 Apr 2026, 10:45
Last Modified
Vulnerability information updated

Description

node-follow-redirects vulnerabilities It was discovered that follow-redirects did not properly protect sensitive user information during redirects. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0155) It was discovered that follow-redirects did not properly remove sensitive information before storage or transfer. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0536) It was discovered that follow-redirects did not properly validate URLs when handling certain inputs. An attacker could possibly use this issue to redirect users to a malicious site, resulting in information disclosure or phishing attacks. (CVE-2023-26159) It was discovered that follow-redirects did not properly clear proxy authentication headers during cross-domain redirects. An attacker could possibly use this issue to cause exposure of sensitive credentials. (CVE-2024-28849)

Affected Systems

  • ubuntunode-follow-redirects

    < 1.2.4-1ubuntu0.18.04.1~esm1 | < 1.2.4-1ubuntu0.20.04.1~esm1 | < 1.14.9+~1.14.1-1ubuntu0.1~esm1

References (5)