CVE-2014-8650: Critical severity Requests-kerberos Project Requests-kerberos vulnerability
Published Dec 15, 2019
·Updated
python-requests-Kerberos through 0.5 does not handle mutual authentication
Affected Software
6 affected componentsFixes available
pip/requests-kerberos<0.6
0.6
Requests-kerberos Project Requests-kerberos<=0.5
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
debian/python-requests-kerberos
0.12.0-20.14.0-40.14.0-6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 15, 2019
CVE Published
via MITRE·09:38 PM
Data Sourced
via MITRE·09:38 PM
Description
Mar 10, 2020
Advisory Published
via GitHub·06:02 PM
Feb 18, 2026
Data Sourced
via Debian·08:49 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-8650?
CVE-2014-8650 is considered a medium severity vulnerability due to its potential impact on mutual authentication.
2
How do I fix CVE-2014-8650?
To fix CVE-2014-8650, upgrade to python-requests-kerberos version 0.6 or later for pip installations or upgrade to versions 0.12.0-2 or 0.14.0-2 for Debian.
3
What kind of systems are affected by CVE-2014-8650?
CVE-2014-8650 affects systems using python-requests-kerberos versions up to and including 0.5, particularly on Debian Linux and pip environments.
4
Is mutual authentication supported in versions after CVE-2014-8650?
Yes, mutual authentication is handled correctly in versions of python-requests-kerberos after 0.5.
5
What are the consequences of not addressing CVE-2014-8650?
Failure to address CVE-2014-8650 may leave systems vulnerable to man-in-the-middle attacks during mutual authentication.