Sensitive information sent insecurely In aiohttp
Description
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
Summary
When following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers.
Impact
The Cookie and Proxy-Authorizations headers could contain sensitive information which may be leaked to an unintended party after following a redirect.
Patch: https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
pypi | 3.13.4 | ||
debian 14 | 3.13.5-1 | ||
debian 11 | 3.7.4-1+deb11u2 | ||
debian 13 | - | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3.