F5-K000141129: Medium severity f5 traffix systems signaling delivery controller vulnerability
Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests Session, if the first request is made with verify=False to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of verify. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000141129?
The vulnerability F5-K000141129 is classified as high severity.
How do I fix F5-K000141129?
To fix F5-K000141129, upgrade to Requests version 2.32.0 or later.
What are the consequences of ignoring F5-K000141129?
Ignoring F5-K000141129 can lead to security risks such as man-in-the-middle attacks due to ignored certificate verification.
Which software is affected by F5-K000141129?
The affected software for F5-K000141129 includes F5 Traffix Systems Signaling Delivery Controller versions 5.1.0 and below.
When was F5-K000141129 reported?
F5-K000141129 was reported on October 2023.