In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0622 | In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a cross-domain redirect. This vulnerability arises from the failure to remove the Authorization header when redirecting across domains. The exposure of the Authorization header to unauthorized actors could potentially allow for account hijacking. |
Github GHSA |
GHSA-cw9j-q3vf-hrrv | Scrapy authorization header leakage on cross-domain redirect |
Ubuntu USN |
USN-7476-1 | Scrapy vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:scrapy:scrapy:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:12:08.239Z
Reserved: 2024-04-10T09:54:50.274Z
Link: CVE-2024-3574
Updated: 2024-08-01T20:12:08.239Z
Status : Analyzed
Published: 2024-04-16T00:15:12.750
Modified: 2025-07-28T14:51:40.343
Link: CVE-2024-3574
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:18Z
EUVD
Github GHSA
Ubuntu USN