First published: Wed Oct 15 2014(Updated: )
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/requests | <2.3.0 | 2.3.0 |
openSUSE | =13.1 | |
Requests | <=2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1830 has a moderate severity rating due to its potential for information disclosure.
To fix CVE-2014-1830, upgrade the requests library to version 2.3.0 or later.
CVE-2014-1830 can expose sensitive information from the Proxy-Authorization header in redirected requests.
CVE-2014-1830 affects requests versions prior to 2.3.0.
CVE-2014-1830 is associated with openSUSE 13.1 when using the affected version of requests.