urllib3-future is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
82
High Risk
Affected versions of urllib3-future may forward sensitive headers such as Authorization, Cookie, and Proxy-Authorization during cross-origin redirects when using certain low-level proxy APIs. This can result in credential leakage to unintended external hosts.
You are affected if you are using a version that falls within the vulnerable range.
urllib3-future is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.0.931 - 2.19.913.
Upgrade the urllib3-future library to the patch version. If upgrading is not possible, avoid using ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) for cross-origin redirects and use ProxyManager.request() instead where applicable.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant