Authorization header leakage in Scrapy version 2.10.1
CVE-2024-3574

7.5HIGH

Key Information:

Vendor

Scrapy

Vendor
CVE Published:
16 April 2024

What is CVE-2024-3574?

In Scrapy version 2.10.1, a security vulnerability exposes the Authorization header during cross-domain redirects. This issue occurs when credentials for server authentication remain in the header, allowing it to be captured by unauthorized third parties. As a result, sensitive information could be compromised, leading to potential account hijacking. It is crucial for users of the affected version to apply the necessary patches to mitigate the risks associated with this vulnerability.

Affected Version(s)

scrapy/scrapy < 2.11.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.