Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade requests | Jul 30, 2024 | Oct 15, 2014 |
| Suse | — | Upgrade python2-requestsUpgrade python3-requestsUpgrade python-requests | Feb 2, 2016 | Oct 15, 2014 |
| Ubuntu | — | Upgrade python-requestsUpgrade python3-requests | Nov 8, 2024 | Oct 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub