guzzlehttp/guzzle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
59
Medium Risk
When allow_redirects.referer is enabled, RedirectMiddleware can copy the URI fragment from the referring request into the generated Referer header on same-scheme redirects. Fragments are client-local and never sent on the original request target, so values such as tokens or secrets in #... can be disclosed to the redirect destination. The fix strips the fragment (in addition to userinfo) before building the redirect Referer value.
You are affected if you are using a version that falls within the vulnerable range and your application enables allow_redirects.referer while following same-scheme redirects for URIs that may contain sensitive fragments.
guzzlehttp/guzzle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.1 - 7.15.0.
Upgrade the guzzlehttp/guzzle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant