VDB

CVE-2022-24737

CVE-2022-24737 PUBLISHED CVSS 6.5 MEDIUM

HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This behavior resulted in the exposure of some cookies when there are redirects originating from the actual host to a third party website. Users are advised to upgrade. There are no known workarounds.

EPSS 0.60% · 69.9th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.60%
69.9th percentile

Affected Products

VendorProductVersions
httpiehttpie< 3.1.0, 0
PyPIhttpie0
fedoraprojectfedora34, 36, 35

Timeline

  • Mar 7, 2022 CVE Published
  • Mar 8, 2022 EPSS Score
  • Apr 28, 2022 EPSS Score
  • Jun 19, 2022 EPSS Score
  • Aug 10, 2022 EPSS Score
  • Oct 1, 2022 EPSS Score
  • Jan 12, 2023 EPSS Score
  • Mar 4, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 25, 2023 EPSS Score
  • Jun 15, 2023 EPSS Score
  • Aug 6, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›