Information Exposure Affecting wpull package, versions [,0.1006.1)
Snyk CVSS
Attack Complexity
Low
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-WPULL-40553
- published 24 Dec 2014
- disclosed 24 Dec 2014
- credit Christopher Foo
Overview
wpull
is a Wget-compatible web downloader and crawler.
Affected versions of this package are vulnerable to Information Exposure. When requesting HTTP content from a HTTPS source, the referer
field is set unconditionally which leaks information.