Safety vulnerability ID: 36546
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Requests before 2.20.0 sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
Latest version: 2.32.3
Python HTTP for Humans.
The Requests package through 2.19.1 before 2018-09-14 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
MISC:https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff: https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ff
MISC:https://github.com/requests/requests/issues/4716: https://github.com/requests/requests/issues/4716
MISC:https://github.com/requests/requests/pull/4718: https://github.com/requests/requests/pull/4718
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application