漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Excon: redact additional sensitive/risky headers when following redirects
Vulnerability Description
Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vulnerability Type
通过发送数据的信息暴露
Vulnerability Title
excon 信息泄露漏洞
Vulnerability Description
excon excon是excon社区的一款HTTP客户端库。 excon 1.5.0之前版本存在信息泄露漏洞,该漏洞源于RedirectFollower中间件在重定向时未能删除额外的敏感标头,并且没有提供自定义标头列表进行过滤,可能导致在初始请求包含不适用于新目标标头信息时意外泄露敏感数据。
CVSS Information
N/A
Vulnerability Type
N/A