Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-35195

Опубликовано: 20 мая 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.6

Описание

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.

РелизСтатусПримечание
devel

needed

esm-apps-legacy/xenial

ignored

bundles requests during build, and requests cannot be patched
esm-apps/bionic

ignored

bundles requests during build, and requests cannot be patched
esm-apps/focal

ignored

bundles requests during build, and requests cannot be patched
esm-apps/jammy

released

22.0.2+dfsg-1ubuntu0.7+esm1
esm-apps/noble

released

24.0+dfsg-1ubuntu1.3+esm1
esm-apps/resolute

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was ignored [bundles requests during build, and requests cannot be patched]
esm-infra-legacy/trusty

ignored

bundles requests during build, and requests cannot be patched
focal

ignored

end of standard support, was ignored [bundles requests during build, and requests cannot be patched]

Показывать по

РелизСтатусПримечание
devel

released

2.32.3+dfsg-1ubuntu1
esm-infra-legacy/trusty

ignored

breaks users, requires source code updates
esm-infra-legacy/xenial

ignored

breaks users, requires source code updates
esm-infra/bionic

ignored

breaks users, requires source code updates
esm-infra/focal

ignored

breaks users, requires source code updates
esm-infra/xenial

ignored

end of ESM support, was ignored [breaks users, requires source code updates]
focal

ignored

end of standard support, was ignored [breaks users, requires source code updates]
jammy

ignored

breaks users, requires source code updates
mantic

ignored

end of life, was ignored [breaks users, requires source code updates]
noble

ignored

breaks users, requires source code updates

Показывать по

EPSS

Процентиль: 27%
0.0034
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
около 2 лет назад

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.

CVSS3: 5.6
nvd
около 2 лет назад

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.

CVSS3: 5.6
msrc
около 2 лет назад

Requests `Session` object does not verify requests after making first request with verify=False

CVSS3: 5.6
debian
около 2 лет назад

Requests is a HTTP library. Prior to 2.32.0, when making requests thro ...

suse-cvrf
около 2 лет назад

Security update for python-requests

EPSS

Процентиль: 27%
0.0034
Низкий

5.6 Medium

CVSS3