Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34487
HistoryMar 03, 2022 - 4:49 a.m.

Information Disclosure

2022-03-0304:49:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
scrapy
vulnerability
information disclosure
cookie headers
malicious urls

EPSS

0.002

Percentile

64.6%

Scrapy is vulnerable to information disclosure. The library does not properly check cookie headers before being redirected to the location URL, allowing an attacker to gain sensitive information or hijack users accounts by redirecting to malicious URLs.