Логотип exploitDog
bind:CVE-2024-3574
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-3574

Количество 4

Количество 4

ubuntu логотип

CVE-2024-3574

почти 2 года назад

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-3574

почти 2 года назад

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-3574

почти 2 года назад

In scrapy version 2.10.1, an issue was identified where the Authorizat ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cw9j-q3vf-hrrv

почти 2 года назад

Scrapy authorization header leakage on cross-domain redirect

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-3574

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-3574

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-3574

In scrapy version 2.10.1, an issue was identified where the Authorizat ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-cw9j-q3vf-hrrv

Scrapy authorization header leakage on cross-domain redirect

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу