by @Smartkeyss
20 Jun 2024

Proxy-Authorization Header Handling Vulnerability in urllib3 (CVE-2024-37891)

by @Smartkeyss
20 Jun 2024

Proxy-Authorization Header Handling Vulnerability in urllib3 (CVE-2024-37891)

CVEs

4.4 Low Severity

PoC video

Summary

urllib3 is a user-friendly HTTP client library for Python. It automatically strips the Proxy-Authorization header during cross-origin redirects to prevent misuse. This vulnerability is low-risk and only affects users who set this header without using urllib3's proxy support.

Description

users/photos/clsevlral8gef1hon15grbvup.jpg

@Smartkeyss

63 posts

I am just curious 😊 I use simple words to explain complicated things. discord: @rxs_s

Total vcoins

0

Social media links

Comments (0)