CVE-2014-1830: Infoleak
Published Oct 15, 2014
·Updated
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
Affected Software
3 affected componentsFixes available
pip/requests<2.3.0
2.3.0
openSUSE openSUSE=13.1
Python Requests<=2.2.1
Event History
Oct 15, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 14, 2022
Advisory Published
02:09 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-1830?
CVE-2014-1830 has a moderate severity rating due to its potential for information disclosure.
2
How do I fix CVE-2014-1830?
To fix CVE-2014-1830, upgrade the requests library to version 2.3.0 or later.
3
What kind of information may be exposed in CVE-2014-1830?
CVE-2014-1830 can expose sensitive information from the Proxy-Authorization header in redirected requests.
4
Which versions of requests are affected by CVE-2014-1830?
CVE-2014-1830 affects requests versions prior to 2.3.0.
5
Is there a specific operating system associated with CVE-2014-1830?
CVE-2014-1830 is associated with openSUSE 13.1 when using the affected version of requests.