CVE-2022-0430

LOW2.4EPSS 0.32%

Exposure of Sensitive information in httpie

Published: 3/16/2022Modified: 11/19/2024
Also known as:GHSA-6pc9-xqrg-wfqwPYSEC-2022-167

Description

httpie is a modern, user-friendly command-line HTTP client for the API era. Prior to version 3.1.0, all cookies saved to session storage are supercookies. At this time, there is no known workaround. Users are recommended to update to version 3.1.0.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1LOW2.4CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

References (7)