Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2296

Опубликовано: 14 мар. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

A flaw was found in the way python-requests set the domain cookie parameter for certain HTTP responses. A remote attacker could use this flaw to modify a cookie to be sent to an arbitrary URL.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.2python-requestsNot affected
Red Hat Ceph Storage 1.3python-requestsNot affected
Red Hat Enterprise Linux 7python-requestsNot affected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-requestsNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-requestsFix deferred
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerpython-requestsFix deferred
Red Hat OpenStack Platform 4python-requestsNot affected
Red Hat Satellite 6python-requestsWill not fix
Red Hat Storage 2python-requestsNot affected
Red Hat Storage 3python-requestsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1202904python-requests: session fixation and cookie stealing vulnerability

EPSS

Процентиль: 83%
0.01945
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

nvd
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.

debian
почти 11 лет назад

The resolve_redirects function in sessions.py in requests 2.1.0 throug ...

suse-cvrf
около 10 лет назад

Security update for python-requests

github
больше 3 лет назад

Python Requests Session Fixation

EPSS

Процентиль: 83%
0.01945
Низкий

4.3 Medium

CVSS2