Description
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
Remediation
References
https://github.com/sindresorhus/got/compare/v12.0.3...v12.1.0
https://github.com/sindresorhus/got/pull/2047
https://github.com/sindresorhus/got/releases/tag/v11.8.5
Related Vulnerabilities
CVE-2022-39202 Vulnerability in npm package matrix-appservice-irc
CVE-2011-3376 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-23461 Vulnerability in npm package jodit
CVE-2022-25890 Vulnerability in npm package wifey
CVE-2022-42004 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind