[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3146-1 requests -- requests

ID: oval:org.secpod.oval:def:601941Date: (C)2015-02-03   (M)2021-06-02
Class: PATCHFamily: unix




Jakub Wilk discovered that in requests, an HTTP library for the Python language, authentication information was improperly handled when a redirect occured. This would allow remote servers to obtain two different types of sensitive information: proxy passwords from the Proxy-Authorization header , or netrc passwords from the Authorization header .

Platform:
Debian 7.0
Product:
python-requests
python3-requests
Reference:
DSA-3146-1
CVE-2014-1829
CVE-2014-1830
CVE    2
CVE-2014-1829
CVE-2014-1830
CPE    3
cpe:/a:python:python3-requests
cpe:/o:debian:debian_linux:7.x
cpe:/a:python:python-requests

© SecPod Technologies