CVE-2022-23607 — Sensitive Information Exposure in Treq
Severity
6.5MEDIUMNVD
GHSA7.5OSV7.5
EPSS
0.2%
top 54.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 1
Description
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies"). This can potentially cause sensitive information to leak upon an HTTP redirect to a different domain., e.g. should `https://example.com` redirect to `http://cloudstorageprovider.com…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 9.0
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2022-23607: python-treq - treq is an HTTP library inspired by requests but written on top of Twisted's Age...↗2022