
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2022-31151 is a security vulnerability affecting the undici package, a Node.js HTTP/1.1 client. The vulnerability was discovered and disclosed in July 2022, where cookie headers remain uncleared during cross-origin redirects. This flaw affects undici versions prior to 5.7.1 (GitHub Advisory).
The vulnerability occurs when cookie headers, which are sensitive headers found in the specification, are not properly cleared during cross-origin redirects. While authorization headers are cleared on cross-origin redirects, cookie headers remained intact. The vulnerability has been assigned a CVSS v3.1 base score of 3.7 (Low) with a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N (GitHub Advisory).
The vulnerability could lead to accidental leakage of cookie information to third-party sites or enable malicious attackers who control the redirection target (such as through an open redirector) to capture sensitive cookie data. This could potentially result in unauthorized access to sensitive information or modification of data (GitHub Advisory).
The vulnerability was patched in undici version 5.7.1 and later versions. For users unable to update immediately, the primary workaround is to ensure redirections are disabled by setting maxRedirections to 0, which is the default configuration (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."