FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2025-03-28 12:03:43 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
181f5e49-b71d-4527-9464-d4624d69acc3py-treq -- sensitive information leak vulnerability

Treq's request methods (`treq.get`, `treq.post`, `HTTPClient.request`, `HTTPClient.get`, etc.) accept cookies as a dictionary.

Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies").

This can potentially cause sensitive information to leak upon an HTTP redirect to a different domain., e.g. should `https://example.com` redirect to `http://cloudstorageprovider.com` the latter will receive the cookie `session`.


Discovery 2022-02-01
Entry 2023-08-31
py37-treq
py38-treq
py39-treq
py310-treq
py311-treq
< 22.1.0

CVE-2022-23607
https://osv.dev/vulnerability/GHSA-fhpf-pp6p-55qc