Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-48rx-c7pg-q66r

Опубликовано: 10 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Excon does not redact additional sensitive/risky headers when following redirects

Impact

The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip.

What kind of vulnerability is it? Who is impacted? This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target.

Patches

Patch exists and is released in v1.5.0

Workarounds

Users can backport the fix to a custom redirect follower middleware.

Пакеты

Наименование

excon

rubygems
Затронутые версииВерсия исправления

< 1.5.0

1.5.0

EPSS

Процентиль: 24%
0.00317
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201
CWE-200
CWE-522

Связанные уязвимости

CVSS3: 6.5
ubuntu
14 дней назад

(Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...)

CVSS3: 6.5
nvd
16 дней назад

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.

CVSS3: 6.5
msrc
14 дней назад

Excon: redact additional sensitive/risky headers when following redirects

CVSS3: 6.5
debian
16 дней назад

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...

EPSS

Процентиль: 24%
0.00317
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201
CWE-200
CWE-522