Candidate: CVE-2022-0235 PublicDate: 2022-01-16 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0235 https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7/ https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7 https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10 Description: node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_node-fetch: upstream_node-fetch: released (2.6.1-7) trusty_node-fetch: ignored (out of standard support) xenial_node-fetch: ignored (out of standard support) bionic_node-fetch: needs-triage focal_node-fetch: needs-triage impish_node-fetch: needs-triage jammy_node-fetch: needs-triage devel_node-fetch: needs-triage