ZeroHour

CVE-2018-18074

PoC ×2
CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

Vendors
pythoncanonicalopensuseredhat
Products
requests, ubuntu linux, leap, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.