Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7585
HistoryOct 10, 2018 - 2:26 a.m.

Information Disclosure

2018-10-1002:26:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.005 Low

EPSS

Percentile

76.4%

requests is vulnerable to information disclosure attacks. The HTTP Authorization header is sent via insecure HTTP channel when a same-hostname HTTPS-to-HTTP redirect is received, allowing remote attackers in the same network to discover credentials by sniffing the network traffic.