openai is vulnerable to Information Disclosure
59
Medium Risk
The AzureOpenAI client attaches a static API key in the api-key header and follows HTTP redirects by default. When the configured endpoint returns a redirect to a different host, the redirected request still includes api-key, which discloses the API key to the redirect target. Custom base URLs, self hosted proxies, and compromised endpoints can produce that redirect. The fix sets redirect to manual for requests that include api-key, so the client stops at the redirect and does not send the key to the next host.
You are affected if you are using a version that falls within the vulnerable range and your AzureOpenAI client sends a static api-key to an endpoint that can redirect to another host.
openai is vulnerable to Information Disclosure in versions 4.41.0 - 7.4.0.
Upgrade the openai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.