First published: Wed Mar 18 2015(Updated: )
The `resolve_redirects` function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mageia Project Mageia | =4.0 | |
Python Requests | =2.1.0 | |
Python Requests | =2.2.1 | |
Python Requests | =2.3.0 | |
Python Requests | =2.4.0 | |
Python Requests | =2.4.1 | |
Python Requests | =2.4.2 | |
Python Requests | =2.4.3 | |
Python Requests | =2.5.0 | |
Python Requests | =2.5.1 | |
Python Requests | =2.5.2 | |
Python Requests | =2.5.3 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =14.10 | |
pip/requests | >=2.1.0<2.6.0 | 2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.