In versions of simple-get prior to 4.0.1, 3.1.1, and 2.8.2, when fetching a remote url with a cookie location response, headers will be followed, potentially resulting in an exposure of the session cookie to a third party.
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed_at": "2022-01-27T23:17:09Z",
"nvd_published_at": "2022-01-26T04:15:00Z",
"severity": "HIGH",
"github_reviewed": true
}