Overview
About vulnerability
Summary
When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.
Impact
The Cookie and Proxy-Authorizations headers could contain sensitive information which may be leaked to an unintended party after following a redirect.
Patch: https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6
Details
- Affected product:
- aiohttp , apache-airflow-providers-http
- Affected packages:
- aiohttp @ 3.8.4.post4+tuxcare (+4 more)