Lucene search

K
ubuntuUbuntuUSN-6155-1
HistoryJun 12, 2023 - 12:00 a.m.

Requests vulnerability

2023-06-1200:00:00
ubuntu.com
37
ubuntu
requests library
proxy-authorization
information leakage
security vulnerability
http protocol
python

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

7.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.8%

Releases

  • Ubuntu 23.04
  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS

Packages

  • requests - elegant and simple HTTP library for Python

Details

Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly
leaked Proxy-Authorization headers. A remote attacker could possibly use
this issue to obtain sensitive information.

OSVersionArchitecturePackageVersionFilename
Ubuntu23.04noarchpython3-requests< 2.28.1+dfsg-1ubuntu1.1UNKNOWN
Ubuntu23.04noarchpython-requests-doc< 2.28.1+dfsg-1ubuntu1.1UNKNOWN
Ubuntu22.10noarchpython3-requests< 2.27.1+dfsg-1ubuntu2.1UNKNOWN
Ubuntu22.10noarchpython-requests-doc< 2.27.1+dfsg-1ubuntu2.1UNKNOWN
Ubuntu22.04noarchpython3-requests< 2.25.1+dfsg-2ubuntu0.1UNKNOWN
Ubuntu22.04noarchpython-requests-doc< 2.25.1+dfsg-2ubuntu0.1UNKNOWN
Ubuntu20.04noarchpython3-requests< 2.22.0-2ubuntu1.1UNKNOWN

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N

7.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

51.8%