follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
- CVSS 3.0 Base Score: 8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade node-follow-redirects | Jul 30, 2024 | Jan 10, 2022 |
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Suse | — | Upgrade libbind9-1600-32bitUpgrade libisccc1600Upgrade wireUpgrade grafanaUpgrade bindUpgrade bind-docUpgrade libisc1606Upgrade libirs1601-32bitUpgrade libirs-develUpgrade libdns1605-32bitUpgrade libbind9-1600Upgrade dracut-saltbootUpgrade libisccfg1600Upgrade python3-bindUpgrade libns1604Upgrade libisccfg1600-32bitUpgrade libns1604-32bitUpgrade bind-develUpgrade libisccc1600-32bitUpgrade libirs1601Upgrade bind-chrootenvUpgrade bind-utilsUpgrade libisc1606-32bitUpgrade spacecmdUpgrade libdns1605Upgrade bind-devel-32bit | Jun 22, 2023 | Jan 10, 2022 |
| Ubuntu | — | Upgrade node-follow-redirects (Ubuntu Pro) | Apr 29, 2026 | Apr 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub