by @Smartkeyss
20 Jun 2024

Proxy-Authorization Header Handling Vulnerability in urllib3 (CVE-2024-37891)

by @Smartkeyss
20 Jun 2024

Proxy-Authorization Header Handling Vulnerability in urllib3 (CVE-2024-37891)

CVEs

4.4 Low Severity

PoC video

Summary

urllib3 is a user-friendly HTTP client library for Python. It automatically strips the Proxy-Authorization header during cross-origin redirects to prevent misuse. This vulnerability is low-risk and only affects users who set this header without using urllib3's proxy support.

Description

users/photos/clsevlral8gef1hon15grbvup.jpg

@Smartkeyss

32 posts

I am just curious 😊 I use simple words to explain complicated things.

Total vcoins

88.9K

Comments (0)