Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-3574

Опубликовано: 16 апр. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

РелизСтатусПримечание
devel

not-affected

2.12.0-2
esm-apps/bionic

released

1.5.0-1ubuntu0.1~esm1
esm-apps/focal

released

1.7.3-1ubuntu0.1~esm1
esm-apps/jammy

released

2.5.1-2ubuntu0.1~esm1
esm-apps/noble

not-affected

2.11.1-1
esm-apps/xenial

ignored

changes too intrusive
focal

ignored

end of standard support, was needed
jammy

needed

mantic

ignored

end of life, was needs-triage
noble

not-affected

2.11.1-1

Показывать по

EPSS

Процентиль: 32%
0.00121
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
почти 2 года назад

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

CVSS3: 7.5
debian
почти 2 года назад

In scrapy version 2.10.1, an issue was identified where the Authorizat ...

CVSS3: 7.5
github
почти 2 года назад

Scrapy authorization header leakage on cross-domain redirect

EPSS

Процентиль: 32%
0.00121
Низкий

7.5 High

CVSS3