April 26, 2023, 9:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

typed-rest-client is a library for Node Rest and Http Clients with typings for use with TypeScript. Users of the typed-rest-client library version 1.7.3 or lower are vulnerable to leak authentication data to 3rd parties. The flow of the vulnerability is as follows: First, send any request with `BasicCredentialHandler`, `BearerCredentialHandler` or `PersonalAccessTokenCredentialHandler`. Second, the target host may return a redirection (3xx), with a link to a second host. Third, the next request will use the credentials to authenticate with the second …

authentication client clients cve data flow host http leak library may node request rest return send target typescript version version 1 vulnerability vulnerable

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Security Engineer

@ BedRock Systems | San Francisco, Boston, DC, Berlin, Munich, Bengaluru

Project Manager - Project Principal Consultant

@ SAP | Istanbul, TR, 34700

Software Security Engineer

@ Ledger | Paris, France