Lucene search

K
ubuntuUbuntuUSN-2382-1
HistoryOct 14, 2014 - 12:00 a.m.

Requests vulnerabilities

2014-10-1400:00:00
ubuntu.com
31

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.0%

Releases

  • Ubuntu 14.04 ESM

Packages

  • requests - elegant and simple HTTP library for Python

Details

Jakub Wilk discovered that Requests incorrectly reused authentication
credentials after being redirected. An attacker could possibly use this
issue to obtain authentication credentials intended for another site.
(CVE-2014-1829, CVE-2014-1830)

OSVersionArchitecturePackageVersionFilename
Ubuntu14.04noarchpython-requests< 2.2.1-1ubuntu0.1UNKNOWN
Ubuntu14.04noarchpython3-requests< 2.2.1-1ubuntu0.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.4

Confidence

Low

EPSS

0.003

Percentile

69.0%