GHSA-7vwr-g6pm-9hc8

    Dashboard / Vulnerabilities / GHSA-7vwr-g6pm-9hc8

    GHSA-7vwr-g6pm-9hc8

    Published: 1 Dec 2023Last Modified: 6 Dec 2024

    Summary: Cookie leakage between different users in fastapi-proxy-lib

    Details: ### Impact In the implementation of version `0.0.1`, requests from different user clients are processed using a shared `httpx.AsyncClient`. However, one oversight is that the `httpx.AsyncClient` will persistently store cookies based on the `set-cookie` response header sent by the target server and share these cookies across different user requests. This results in a cookie leakage issue among all user clients sharing the same `httpx.AsyncClient`. ### Patches It's fixed in `0.1.0` ### Workarounds If you insist `0.0.1`: - Do not use `ForwardHttpProxy` at all. - Do not use `ReverseHttpProxy` or `ReverseWebSocketProxy` for any servers that may potentially send a `set-cookie` response. **However, it's best to upgrade to the latest version.** ### References fixed in [#10](https://github.com/WSH032/fastapi-proxy-lib/pull/10)

    Affected packages

    Package

    Name: fastapi-proxy-lib

    Purl: pkg:pypi/fastapi-proxy-lib

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.1.0

    Affected versions

    0.0.1b0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7vwr-g6pm-9hc8 | CVE-DB