Back to search
CVE-2018-18074
Published: Oct 9, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3790-1
vendor-advisory
x_refsource_UBUNTU
USN-3790-2
vendor-advisory
x_refsource_UBUNTU
openSUSE-SU-2019:1754
vendor-advisory
x_refsource_SUSE
RHSA-2019:2035
vendor-advisory
x_refsource_REDHAT
https://www.oracle.com/security-alerts/cpujul2022.html
x_refsource_MISC
https://bugs.debian.org/910766
x_refsource_MISC
https://github.com/requests/requests/issues/4716
x_refsource_MISC
https://github.com/requests/requests/pull/4718
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now