cbcvebase.
CVE-2024-3574
published 2024-04-16

CVE-2024-3574: In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party…

PriorityP345high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.64%
47.3th percentile
In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianpython-scrapy< python-scrapy 2.11.1-1 (forky)python-scrapy 2.11.1-1 (forky)
scrapyscrapy< 2.11.12.11.1
scrapyscrapy>= 0 < 1.8.41.8.4
scrapyscrapy>= 2 < 2.11.12.11.1
scrapyscrapy_scrapy>= unspecified < 2.11.12.11.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.