MEDIUM4.0
GHSA-8jp9-mpv9-98rj
amphp/http-client Header leakage on cross-domain redirects
Quick fix
GHSA-8jp9-mpv9-98rj — amphp/http-client: upgrade to the fixed version with the command below.
composer require amphp/http-client:^4.4.0Details
amphp/http-client has a security weakness that might leak sensitive request headers from the initial request to the redirected host on cross-domain redirects, which were not removed correctly. `Message::setHeaders` does not replace the entire set of headers, but only operates on the headers matching the given array keys.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/amphp/http-client
Introduced in:
4.0.0Fixed in: 4.4.0Fix
composer require amphp/http-client:^4.4.0