Skip to content

urllib may leak sensitive HTTP headers to a third-party web site #77842

@artem-smotrakov

Description

@artem-smotrakov
BPO 33661
Nosy @orsenthil, @jwilk, @alex, @vadmium, @native-api, @artem-smotrakov, @eamanu, @kyoshidajp, @tirkarthi, @epicfaace
PRs
  • bpo-33661: Clear Authorization header when redirect to cross-site #11292
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2018-05-27.14:20:06.497>
    labels = ['type-security', 'library']
    title = 'urllib may leak sensitive HTTP headers to a third-party web site'
    updated_at = <Date 2019-08-14.04:01:33.275>
    user = 'https://github.com/artem-smotrakov'

    bugs.python.org fields:

    activity = <Date 2019-08-14.04:01:33.275>
    actor = 'epicfaace'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)']
    creation = <Date 2018-05-27.14:20:06.497>
    creator = 'artem.smotrakov'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 33661
    keywords = ['patch']
    message_count = 11.0
    messages = ['317793', '317818', '317824', '318453', '319880', '332381', '332408', '332561', '332571', '332719', '349640']
    nosy_count = 10.0
    nosy_names = ['orsenthil', 'jwilk', 'alex', 'martin.panter', 'Ivan.Pozdeev', 'artem.smotrakov', 'eamanu', 'kyoshidajp', 'xtreak', 'epicfaace']
    pr_nums = ['11292']
    priority = 'normal'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue33661'
    versions = ['Python 3.5']

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      stdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions