Описание
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.4.3-6 |
| esm-infra-legacy/trusty | released | 2.2.1-1ubuntu0.2 |
| lucid | DNE | |
| precise | not-affected | 0.8.2-1 |
| trusty | released | 2.2.1-1ubuntu0.2 |
| trusty/esm | released | 2.2.1-1ubuntu0.2 |
| upstream | released | 2.6.0,2.4.3-6 |
| utopic | released | 2.3.0-1ubuntu0.1 |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
The resolve_redirects function in sessions.py in requests 2.1.0 throug ...
EPSS
6.8 Medium
CVSS2