CVE-2022-24719 is a medium-severity vulnerability affecting Fluture-Node versions 4.0.0 and 4.0.1, a Node.js library for FP-style HTTP and streaming. It allows for the leakage of confidential headers (e.g., Authorization, Cookie) when the followRedirects or followRedirectsWith functions are used and a redirect occurs to a third-party domain or an unencrypted HTTP connection. The attack vector is network-based with low attack complexity, requiring user interaction, and could lead to partial confidentiality and integrity compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:a:fluture-node_project:fluture-node:4.0.0:*:*:*:*:node.js:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:fluture-node_project:fluture-node:4.0.1:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.