CVE-2018-18074
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 7.44% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-522
- Affected
- python/requests · canonical/ubuntu linux · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- http://docs.python-requests.org/en/master/community/updates/#release-and-version-historyRelease Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2035Third Party Advisory
- https://bugs.debian.org/910766Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ffPatch, Third Party Advisory
- https://github.com/requests/requests/issues/4716Exploit, Patch, Third Party Advisory
- https://github.com/requests/requests/pull/4718Patch, Third Party Advisory
- https://usn.ubuntu.com/3790-1/Third Party Advisory
- https://usn.ubuntu.com/3790-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html
- http://docs.python-requests.org/en/master/community/updates/#release-and-version-historyRelease Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00024.htmlMailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2035Third Party Advisory
- https://bugs.debian.org/910766Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/requests/requests/commit/c45d7c49ea75133e52ab22a8e9e13173938e36ffPatch, Third Party Advisory
- https://github.com/requests/requests/issues/4716Exploit, Patch, Third Party Advisory
- https://github.com/requests/requests/pull/4718Patch, Third Party Advisory
- https://usn.ubuntu.com/3790-1/Third Party Advisory
- https://usn.ubuntu.com/3790-2/Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.