CVE-2022-23607
Description
treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (treq.get, treq.post, etc.) and treq.client.HTTPClient constructor accept cookies as a dictionary. Such cookies are not bound to a single domain, and are therefore sent to *every* domain ("supercookies"). This can potentially cause sensitive information to leak upon an HTTP redirect to a different domain., e.g. should https://example.com redirect to http://cloudstorageprovider.com the latter will receive the cookie session. Treq 2021.1.0 and later bind cookies given to request methods (treq.request, treq.get, HTTPClient.request, HTTPClient.get, etc.) to the origin of the *url* parameter. Users are advised to upgrade. For users unable to upgrade Instead of passing a dictionary as the *cookies* argument, pass a http.cookiejar.CookieJar instance with properly domain- and scheme-scoped cookies in it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
treqPyPI | < 22.1.0 | 22.1.0 |
Affected products
7- ghsa-coords4 versionspkg:pypi/treqpkg:rpm/opensuse/python-treq&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/python-treq&distro=SUSE%20Package%20Hub%2015%20SP3pkg:rpm/opensuse/python-treq&distro=openSUSE%20Tumbleweed
< 22.1.0+ 3 more
- (no CPE)range: < 22.1.0
- (no CPE)range: < 20.3.0-bp153.2.3.1
- (no CPE)range: < 20.3.0-bp153.2.3.1
- (no CPE)range: < 22.1.0-1.1
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-fhpf-pp6p-55qcghsaADVISORY
- github.com/twisted/treq/security/advisories/GHSA-fhpf-pp6p-55qcnvdMitigationThird Party AdvisoryWEB
- lists.debian.org/debian-lts-announce/2022/03/msg00025.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-23607ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/treq/PYSEC-2022-26.yamlghsaWEB
- github.com/twisted/treq/commit/1da6022cc880bbcff59321abe02bf8498b89efb2ghsaWEB
- github.com/twisted/treq/releases/tag/release-22.1.0ghsaWEB
- huntr.dev/bounties/3c9204fc-a3d1-4441-8599-924c5f57e7ae/ghsaWEB
News mentions
0No linked articles in our index yet.