aiosonic is vulnerable to Cleartext Transmission of Sensitive Information
37
Low Risk
When following redirects, the client decides whether to strip the Authorization header by comparing only the URL netloc and never inspects the scheme. A redirect from an https URL to an http URL on the same host keeps an identical netloc, so the credential is not dropped and is re-sent in cleartext over the plaintext leg. A passive observer on that network path can capture the bearer token or basic credentials. The fix strips sensitive credentials when a redirect downgrades from https to a non-https scheme.
You are affected if you are using a version that falls within the vulnerable range and you follow redirects with an Authorization header against an origin that can redirect to an http URL on the same host.
aiosonic is vulnerable to Cleartext Transmission of Sensitive Information in versions 0.0.1 - 1.0.3.
Upgrade the aiosonic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant