Weak credential policy In requests
Description
Insufficiently Protected Credentials in Requests The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 2.20.0 | ||
debian 14 | 2.20.0-1 | ||
debian 12 | 2.20.0-1 | ||
debian 11 | 2.20.0-1 | ||
debian 13 | 2.20.0-1 | ||
rpm rhel7 | 0:9.0.3-7.el7_8 | ||
rpm rhel8 | 0:9.0.3-16.el8 | ||
rpm rhel6 | - | - | |
rpm rhel7 | 0:2.6.0-5.el7 | ||
rpm rhel7 | 0:15.1.0-4.el7_8 |
1-10 of 13
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.