QID 994794
Date Published: 2023-08-10
QID 994794: Python (Pip) Security Update for requests (GHSA-pg2w-x9wp-vw92)
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-pg2w-x9wp-vw92 for updates and patch information.
Vendor References
- GHSA-pg2w-x9wp-vw92 -
github.com/advisories/GHSA-pg2w-x9wp-vw92
CVEs related to QID 994794
Software Advisories
| Advisory ID | Software | Component | Link |
|---|