CVE-2015-2296: Medium severity mageia vulnerability
The resolveredirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Other sources
The resolveredirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2296?
CVE-2015-2296 has a medium severity rating due to its potential for session fixation attacks.
How do I fix CVE-2015-2296?
To fix CVE-2015-2296, upgrade the requests library to version 2.6.0 or later.
What versions of requests are affected by CVE-2015-2296?
CVE-2015-2296 affects requests library versions 2.1.0 through 2.5.3.
What type of attack does CVE-2015-2296 enable?
CVE-2015-2296 enables session fixation attacks due to a vulnerability in cookie handling during redirects.
Which platforms are affected by CVE-2015-2296?
CVE-2015-2296 affects various platforms that use the vulnerable versions of the requests library, including mageia and certain Ubuntu versions.