漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Authorization Header Leak During Cross-Domain Redirect in scrapy/scrapy
Vulnerability Description
In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
Scrapy 信息泄露漏洞
Vulnerability Description
Scrapy是一个用Python编写的自由且开源的网络爬虫框架。 Scrapy 2.10.1版本存在信息泄露漏洞,该漏洞源于跨域重定向时未能删除授权标头,将授权标头暴露给未经授权的参与者可能会导致帐户劫持。
CVSS Information
N/A
Vulnerability Type
N/A