Описание
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| requests | fixed | 2.3.0-1 | package |
Примечания
https://github.com/kennethreitz/requests/issues/1885
Связанные уязвимости
ubuntu
больше 11 лет назад
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
redhat
около 12 лет назад
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
nvd
больше 11 лет назад
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
CVSS3: 5.3
github
больше 3 лет назад
Exposure of Sensitive Information to an Unauthorized Actor in Requests