aiosonic is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
68
Medium Risk
When routing HTTPS requests through a proxy, the client keys proxy connections by the proxy address and reuses a completed CONNECT tunnel for later requests to a different destination origin. A request intended for one origin is therefore sent inside the TLS stream established to a previously contacted origin. The earlier origin can observe requests, headers, credentials, and bodies meant for a different destination. The fix reconnects the proxy tunnel when the destination origin changes and binds the tunneled TLS handshake to the destination hostname.
You are affected if you are using a version that falls within the vulnerable range and you send HTTPS requests to more than one destination origin through the same HTTPS proxy.
aiosonic is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.18.1 - 1.0.3.
Upgrade the aiosonic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant