漏洞标题
scrapy/scrapy 中跨域重定向时的授权标头泄露
漏洞描述信息
在Scrapy 2.10.1版本中,发现了一个问题,即在跨域重定向时,包含服务器身份验证凭据的Authorization头被泄露到第三方网站。这个漏洞源于在跨域重定向时未能删除Authorization头。未经授权的演员暴露Authorization头可能潜在地允许账户劫持。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
漏洞类别
信息暴露
漏洞标题
Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy
漏洞描述信息
In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.
CVSS信息
N/A
漏洞类别
信息暴露
漏洞标题
Scrapy 信息泄露漏洞
漏洞描述信息
Scrapy是一个用Python编写的自由且开源的网络爬虫框架。 Scrapy 2.10.1版本存在信息泄露漏洞,该漏洞源于跨域重定向时未能删除授权标头,将授权标头暴露给未经授权的参与者可能会导致帐户劫持。
CVSS信息
N/A
漏洞类别
信息泄露