CVE-2023-32681 is a vulnerability in the Requests HTTP library (versions 2.3.0 through 2.30.0), affecting products like fedoraproject and python-requests, where Proxy-Authorization headers are inadvertently leaked to destination servers during HTTPS redirects. This medium-severity vulnerability (CVSS 6.1) has a network attack vector with high attack complexity and user interaction required, potentially leading to high confidentiality impact by exposing proxy credentials. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.31.0CPE matchmatch criteria | cpe:2.3:a:python:requests:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Add-on for Microsoft Office 365 - October 2024
Oct 17, 2024Third-Party Package Updates in Splunk Add-on Builder - January 2024
Jan 30, 2024CVE-2023-32681
Jun 13, 2023python-requests: Unintended leak of Proxy-Authorization header
May 23, 2023Unintended leak of Proxy-Authorization header in requests
May 22, 2023Unintended leak of Proxy-Authorization header in requests
May 9, 2023