Vulnerabilities |
2 via 14 paths |
|---|---|
Dependencies |
178 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
high severity
new
- Vulnerable module: http-cache-semantics
- Introduced through: pacote@22.0.0 and @npmcli/arborist@10.0.3
Detailed paths
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › @npmcli/metavuln-calculator@10.0.0 › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › @npmcli/metavuln-calculator@10.0.0 › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
Overview
Affected versions of this package are vulnerable to Improper Authorization via improper validation of security-zeroed cache entries when processing client max-stale directives. An unauthenticated attacker can request the same URL with a large max-stale value to retrieve cached responses belonging to other users, including Set-Cookie session credentials from shared-cache entries that were deliberately zeroed for security reasons.
Remediation
There is no fixed version for http-cache-semantics.
References
high severity
new
- Vulnerable module: http-cache-semantics
- Introduced through: pacote@22.0.0 and @npmcli/arborist@10.0.3
Detailed paths
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › @npmcli/metavuln-calculator@10.0.0 › pacote@22.0.0 › npm-registry-fetch@20.0.1 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
-
Introduced through: npm-pkgbuild@arlac77/npm-pkgbuild › @npmcli/arborist@10.0.3 › @npmcli/metavuln-calculator@10.0.0 › pacote@22.0.0 › sigstore@5.0.0 › @sigstore/sign@5.0.0 › make-fetch-happen@16.0.1 › http-cache-semantics@4.3.0
Overview
Affected versions of this package are vulnerable to Origin Validation Error via the _varyMatches() function, which fails to properly handle Vary: * (wildcard) headers due to byte-for-byte string comparison. An attacker can request URLs previously fetched by other clients to receive cached responses intended for different users, disclosing sensitive information across clients. The Vary: * directive signals that a response is uncacheable for any other request, but the flawed comparison allows the wildcard to be bypassed, enabling cross-client cache disclosure.
Remediation
There is no fixed version for http-cache-semantics.