aiosonic is vulnerable to Sensitive Information Disclosure
68
Medium Risk
aiosonic's redirect handler strips only the Authorization header when a response redirects the client to a different host. When an application follows redirects with follow=True and supplies a Cookie or Proxy-Authorization header, those credentials are forwarded unchanged to whatever host the origin server names in Location:. A redirect to an attacker-controlled or compromised host receives the caller's session cookies or proxy credentials. The fix also drops Cookie and Proxy-Authorization headers when the redirect target host changes.
You are affected if you are using a version that falls within the vulnerable range and your application follows redirects with follow=True while passing a Cookie or Proxy-Authorization header.
aiosonic is vulnerable to Sensitive Information Disclosure in versions 0.2.0 - 1.0.2.
Upgrade the aiosonic library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant