The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade requests | Jul 30, 2024 | Mar 18, 2015 |
| Suse | — | Upgrade python3-pipUpgrade python-jmespathUpgrade python39-setuptoolsUpgrade python-paramikoUpgrade python3-requestsUpgrade python-chardetUpgrade python3-urllib3Upgrade python3-certifiUpgrade python-requestsUpgrade python3-paramikoUpgrade python3-plyUpgrade python2-pipUpgrade python-plyUpgrade python39-pipUpgrade python2-requestsUpgrade python3-jsonschemaUpgrade python3-chardetUpgrade python-jsonschemaUpgrade python-certifiUpgrade python-pipUpgrade python-urllib3Upgrade python3-jmespathUpgrade python3-pip-wheel | Feb 2, 2016 | Mar 18, 2015 |
| Ubuntu | — | Upgrade python-requestsUpgrade python3-requests | Nov 8, 2024 | Mar 18, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub