Lucene search

K
redosRedosROS-20240408-11
HistoryApr 08, 2024 - 12:00 a.m.

ROS-20240408-11

2024-04-0800:00:00
redos.red-soft.ru
12
python requests library
http
data protection
unauthorized access
vulnerability

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.8%

A vulnerability in the HTTP Requests library of the Python Requests programming language is related to insufficient protection of service data.
inadequate protection of proprietary data. Exploitation of the vulnerability could allow an attacker acting remotely,
gain unauthorized access to protected information

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64python3-requests<= 2.26.0-4UNKNOWN

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.8%