Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34127
HistoryFeb 10, 2022 - 5:03 a.m.

Information Disclosure

2022-02-1005:03:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

0.001 Low

EPSS

Percentile

48.8%

follow-redirects is vulnerable to information disclosure. The vulnerability exists because the HTTP Authorization header is sent via an insecure HTTP channel when a same-hostname HTTPS-to-HTTP redirect is received, allowing attackers in the same network to discover credentials by sniffing the network traffic.