Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40650
HistoryMay 24, 2023 - 2:21 a.m.

Unintended Leaks Of Proxy-Authorization Header

2023-05-2402:21:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
34
proxy-authorization
vulnerability
requests
https
credentials
redirects

0.002 Low

EPSS

Percentile

51.8%

requests is vulnerable to Unintended Leaks Of Proxy-Authorization Header. The vulnerability exists in the rebuild_proxies function of sessions.py when the credentials are supplied in the URL user information component such as https://username:password@proxy:8080, which allows an attacker to gain Proxy-Authorization header information through the destination servers during redirects to an HTTPS origin.