This advisory has been withdrawn because the vulnerability originates from a dependency. For more information, see the Maintainer comments in https://huntr.com/bounties/ab55dfdd-2a60-437a-a832-e3efe3d264ac.
When fetching a remote url with Cookie if it get Location response header then it will follow that url and try to fetch that url with provided cookie . So cookie is leaked here to thirdparty. Ex: you try to fetch example.com with cookie and if it get redirect url to attacker.com then it fetch that redirect url with provided cookie .
{
"cwe_ids": [
"CWE-359",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2022-04-28T20:45:25Z",
"nvd_published_at": "2022-04-15T23:15:00Z",
"severity": "MODERATE"
}