漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
Vulnerability Description
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
urllib3 信息泄露漏洞
Vulnerability Description
urllib3是urllib3开源的一款Python HTTP库。该产品具有线程安全连接池、文件发布支持等。 urllib3 1.23版本至2.7.0之前版本存在信息泄露漏洞,该漏洞源于通过ProxyManager低层API的跨源重定向仍转发敏感标头。
CVSS Information
N/A
Vulnerability Type
N/A