CVE-2022-0235Medium· 6.1▾ Sunlitnode-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.7%
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
node-fetch < 2.6.7node-fetch >= 3.0.0, < 3.1.1sinec_ins < 1.0sinec_ins = 1.0debian_linux = 10.0Upgrade past the affected range:
node-fetch 3.1.1sinec_ins 1.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-2596Medium· 5.9Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
CVE-2026-100723High· 7.5vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength === length) to Buffers returned from host builtin modules
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header
CVE-2020-15250Medium· 4.4Information disclosure in JUnit4
CVE-2021-41277Critical· 10.0Metabase is an open source data analytics platform
CVE-2021-34485Medium· 5.0.NET Core and Visual Studio Information Disclosure Vulnerability