← back
CVE-2022-24737

Exposure of Sensitive Information to an Unauthorized Actor in httpie

CVSS 6.5 MEDIUMEPSS 1.6%CWE-200
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 1.6%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
07 Mar 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This behavior resulted in the exposure of some cookies when there are redirects originating from the actual host to a third party website. Users are advised to upgrade. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
httpie · httpie

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →