websockets is vulnerable to Information Disclosure
61
Medium Risk
The asyncio and legacy WebSocket clients replay any configured Authorization, Cookie, and Proxy-Authorization headers unchanged when following a redirect to a different origin. A cross-origin redirect target then receives those credentials in the follow-up connection attempt. This exposes secrets that were only meant for the original host to whatever server controls the redirect. The fix strips these headers from additional_headers before reconnecting to the redirect target.
You are affected if you are using a version that falls within the vulnerable range and your client sends Authorization, Cookie, or Proxy-Authorization headers while following redirects to servers on a different origin. The legacy client is affected from 8.0; the asyncio client from 13.1.
websockets is vulnerable to Information Disclosure in versions 8.0 - 16.0.
Upgrade the websockets library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.