Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
{
"nvd_published_at": "2014-10-15T14:55:00Z",
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed_at": "2022-07-07T22:49:51Z",
"github_reviewed": true
}