Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2022-0235
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-0235
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0235.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-0235
Aliases
GHSA-r683-j2x4-v87g
Downstream
DEBIAN-CVE-2022-0235
DLA-3222-1
RHSA-2023:0050
RHSA-2023:0612
RHSA-2023:1742
SUSE-SU-2022:1459-1
SUSE-SU-2022:1461-1
SUSE-SU-2022:1462-1
SUSE-SU-2022:1466-1
SUSE-SU-2022:1694-1
SUSE-SU-2022:1717-1
UBUNTU-CVE-2022-0235
USN-6158-1
Related
ALSA-2023:0050
RLSA-2023:0050
SUSE-SU-2022:1459-1
SUSE-SU-2022:1461-1
SUSE-SU-2022:1462-1
SUSE-SU-2022:1466-1
SUSE-SU-2022:1694-1
SUSE-SU-2022:1717-1
Published
2022-01-16T17:15:07Z
Modified
2025-10-10T03:43:08.691279Z
Severity
6.1 (Medium)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS Calculator
Summary
[none]
Details
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
References
https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf
https://github.com/node-fetch/node-fetch/commit/36e47e8a6406185921e4985dcbeff140d73eaa10
https://huntr.dev/bounties/d26ab655-38d6-48b3-be15-f9ad6b6ae6f7
https://lists.debian.org/debian-lts-announce/2022/12/msg00007.html
Affected packages
Git
/
github.com/node-fetch/node-fetch
Affected ranges
Type
GIT
Repo
https://github.com/node-fetch/node-fetch
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
36e47e8a6406185921e4985dcbeff140d73eaa10
Affected versions
v1.*
v1.4.0
v1.4.1
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v2.*
v2.0.0
v2.0.0-alpha.1
v2.0.0-alpha.3
v2.0.0-alpha.4
v2.0.0-alpha.5
v2.0.0-alpha.6
v2.0.0-alpha.7
v2.0.0-alpha.8
v2.0.0-alpha.9
v2.1.0
v2.1.1
v2.1.2
v2.2.0
v2.2.1
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v3.*
v3.0.0
v3.0.0-beta.1
v3.0.0-beta.10
v3.0.0-beta.5
v3.0.0-beta.6
v3.0.0-beta.6-exportfix
v3.0.0-beta.7
v3.0.0-beta.8
v3.0.0-beta.9
v3.1.0
CVE-2022-0235 - OSV