CVE-2014-1829: Infoleak
Published Oct 15, 2014
·Updated
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
Affected Software
5 affected componentsFixes available
pip/requests<2.3.0
2.3.0
Debian Debian Linux=7.0
Python Requests<=2.2.1
Canonical Ubuntu Linux=14.04
Mageia Mageia=4.0
Remediation
Patch Available
Event History
Oct 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
03:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-1829?
CVE-2014-1829 is classified as a medium severity vulnerability due to the potential for information disclosure.
2
How do I fix CVE-2014-1829?
To fix CVE-2014-1829, upgrade the Requests library to version 2.3.0 or later.
3
What is affected by CVE-2014-1829?
CVE-2014-1829 affects Requests library versions prior to 2.3.0, including specific versions in Debian, Ubuntu, Mageia, and Python.
4
What type of vulnerability is CVE-2014-1829?
CVE-2014-1829 is an information disclosure vulnerability that allows remote servers to access netrc passwords.
5
Can CVE-2014-1829 be exploited remotely?
Yes, CVE-2014-1829 can be exploited remotely if a user interacts with malicious redirected requests.