CVE-2020-11021 describes a vulnerability in the NPM @actions/http-client library (versions prior to 1.0.8) where Authorization headers can be inadvertently disclosed to an incorrect domain during specific redirect scenarios. This occurs when an HTTP request with an Authorization header is redirected (302) to a different domain or hostname, causing the header to be sent to the unintended recipient. This vulnerability is rated High severity (CVSS 7.5) due to its network-based attack vector and low attack complexity, potentially leading to a complete compromise of confidentiality (C:H) if sensitive authorization tokens are exposed. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, the vulnerability is not listed on the KEV catalog, suggesting it is not currently a widespread threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.8CPE matchmatch criteria | cpe:2.3:a:http-client_project:http-client:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.