linuxfabrik-lib Package Vulnerability: Potential Credential Exposure
An early warning has been issued regarding the linuxfabrik-lib package, which reportedly forwards credential headers across cross-origin redirects, potentially exposing sensitive tokens. Users of linuxfabrik-lib (pypi) versions prior to 6.0.0 are advised to upgrade.
What happened
The linuxfabrik-lib package, available on PyPI, appears to have a vulnerability where the fetch() function forwards credential headers across cross-origin redirects. This behavior could potentially expose sensitive tokens to malicious servers. The issue is under investigation and has been tracked under the ID GHSA-4JC5-G844-4X33.
To mitigate the risk of credential exposure, it is recommended to upgrade linuxfabrik-lib to version 6.0.0 or later. The vulnerability affects versions of linuxfabrik-lib (pypi) prior to 6.0.0. For more detailed information, please consult the primary sources provided.
How 0Day mitigates this
linuxfabrik-lib is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.