node-fetch Project node-fetch 2.1.2 for Node.js

CPE Details

node-fetch Project node-fetch 2.1.2 for Node.js
2.1.2
2020-09-11
17h15 +00:00
2020-09-11
17h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:node-fetch_project:node-fetch:2.1.2:*:*:*:*:node.js:*:*

Informations

Vendor

node-fetch_project

Product

node-fetch

Version

2.1.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-0235 2022-01-15 23h00 +00:00 node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
6.1
Medium
CVE-2020-15168 2020-09-10 16h25 +00:00 node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.
5.3
Medium