Related Vulnerabilities: CVE-2022-33987  

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

Description

The MITRE CVE dictionary describes this issue as:

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

Additional Information

  • Bugzilla 2102001: CVE-2022-33987 got: missing verification of requested URLs allows redirects to UNIX sockets
  • FAQ: Frequently asked questions about CVE-2022-33987