漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect
Vulnerability Description
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following redirects to a different origin, aiohttp drops the Authorization header, but retains the Cookie and Proxy-Authorization headers. This issue has been patched in version 3.13.4.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
aiohttp 信息泄露漏洞
Vulnerability Description
aiohttp是aio-libs开源的一个开源的用于 asyncio 和 Python 的异步 HTTP 客户端/服务器框架。 aiohttp 3.13.4之前版本存在信息泄露漏洞,该漏洞源于在重定向到不同来源时,aiohttp丢弃Authorization标头但保留Cookie和Proxy-Authorization标头。
CVSS Information
N/A
Vulnerability Type
N/A