Cookie and Authorization headers are leaked when following cross-origin redirects in twited.web.client.RedirectAgent
and twisted.web.client.BrowserLikeRedirectAgent
.
{ "nvd_published_at": "2022-02-07T22:15:00Z", "cwe_ids": [ "CWE-200", "CWE-346" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-02-07T22:36:00Z" }