MEDIUM
GHSA-hg6j-4rv6-33pg
AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
Details
### Summary
Cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect.
### Impact
If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect.
### Workaround
If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.
-----
Patch: https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478
Are you affected?
Enter the version of the package you're using.