CVE-2018-18074
PoC ×2—CVSS 3.1
7.5 high
EPSS
7%p94
Published
()
Modified
Description
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
In the news0 stories
No ingested article mentions this CVE yet.