node-fetch forwards secure headers such as authorization, www-authenticate, cookie, & cookie2 when redirecting to a untrusted site.
{
    "nvd_published_at": "2022-01-16T17:15:00Z",
    "github_reviewed_at": "2022-01-18T22:51:22Z",
    "cwe_ids": [
        "CWE-173",
        "CWE-200",
        "CWE-601"
    ],
    "severity": "HIGH",
    "github_reviewed": true
}