Scrapy is vulnerable to information disclosure. The library does not properly check cookie headers before being redirected to the location
URL, allowing an attacker to gain sensitive information or hijack users accounts by redirecting to malicious URLs.
github.com/advisories/GHSA-cjvr-mfj7-j4j8
github.com/scrapy/scrapy/commit/290e2a27266850c50ba0c1bc753c5ce66b78363a
github.com/scrapy/scrapy/commit/8ce01b3b76d4634f55067d6cfdf632ec70ba304a
huntr.dev/bounties/3da527b1-2348-4f69-9e88-2e11a96ac585
huntr.dev/bounties/3da527b1-2348-4f69-9e88-2e11a96ac585/
lists.debian.org/debian-lts-announce/2022/03/msg00021.html