Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2296

Опубликовано: 18 мар. 2015
Источник: debian
EPSS Низкий

Описание

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
requestsfixed2.4.3-6package
requestsnot-affectedwheezypackage

Примечания

  • https://github.com/kennethreitz/requests/commit/3bd8afbff29e50b38f889b2f688785a669b9aafc

EPSS

Процентиль: 83%
0.01945
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

redhat
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

nvd
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

suse-cvrf
около 10 лет назад

Security update for python-requests

github
больше 3 лет назад

Python Requests Session Fixation

EPSS

Процентиль: 83%
0.01945
Низкий