When fetching an url with a link to an external site (Redirect), the users Cookies & Autorisation headers are leaked to the third party application. According to the same-origin-policy, the header should be "sanitized."
{ "nvd_published_at": "2022-05-12T11:15:00Z", "cwe_ids": [ "CWE-200", "CWE-212" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-05-25T19:27:47Z" }