CVE-2014-1829
published 2014-10-15CVE-2014-1829: Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
PriorityP429medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.20%
80.5th percentile
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | requests | < requests 2.3.0-1 (bookworm) | requests 2.3.0-1 (bookworm) |
| mageia | mageia | — | — |
| python | requests | <= 2.2.1 | — |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0 | 2.3.0 |
| python | requests | >= 0 < 2.2.1-1ubuntu0.1 | 2.2.1-1ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Requests
ghsa·2022-05-17
CVE-2014-1829 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Requests
osv·2022-05-17
CVE-2014-1829 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
OSV
CVE-2014-1829: Requests (aka python-requests) before 2
osv·2014-10-15·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829: Requests (aka python-requests) before 2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
OSV
requests vulnerabilities
osv·2014-10-14·CVSS 5.0
CVE-2014-1829 [MEDIUM] requests vulnerabilities
requests vulnerabilities
Jakub Wilk discovered that Requests incorrectly reused authentication
credentials after being redirected. An attacker could possibly use this
issue to obtain authentication credentials intended for another site.
(CVE-2014-1829, CVE-2014-1830)
Ubuntu
Requests vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 5.0
CVE-2014-1829 [MEDIUM] Requests vulnerabilities
Title: Requests vulnerabilities
Summary: Requests could be made to expose authentication credentials over the
network.
Jakub Wilk discovered that Requests incorrectly reused authentication
credentials after being redirected. An attacker could possibly use this
issue to obtain authentication credentials intended for another site.
(CVE-2014-1829, CVE-2014-1830)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-1829: requests - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a ne...
vendor_debian·2014·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829: requests - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a ne...
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
Scope: local
bookworm: resolved (fixed in 2.3.0-1)
bullseye: resolved (fixed in 2.3.0-1)
forky: resolved (fixed in 2.3.0-1)
sid: resolved (fixed in 2.3.0-1)
trixie: resolved (fixed in 2.3.0-1)
Red Hat
python-requests: redirect can expose netrc password
vendor_redhat·2013-12-25·CVSS 5.0
CVE-2014-1829 [MEDIUM] CWE-285 python-requests: redirect can expose netrc password
python-requests: redirect can expose netrc password
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
Statement: This issue did not affect the versions of python-requests as shipped with Red Hat Enterprise Linux 7 as they included a fix for this issue at GA.
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: python-requests (Red Hat Enterprise Linux 7) - Not affected
Package: python-requests (Red Hat OpenStack Platform 3) - Will not fix
Package: pyt
No detection rules found.
Nuclei
Titan FTP Server Search Function < 10.40 - User Enumeration
nuclei·CVSS 5.0
CVE-2014-1842 [MEDIUM] Titan FTP Server Search Function < 10.40 - User Enumeration
Titan FTP Server Search Function < 10.40 - User Enumeration
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability in the web interface search functionality. Remote attackers can list all existing users by submitting "/../" in the search bar, enabling user enumeration and reconnaissance.
Template:
id: CVE-2014-1842
info:
name: Titan FTP Server Search Function < 10.40 - User Enumeration
author: pussycat0x
severity: medium
description: |
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability in the web interface search functionality. Remote attackers can list all existing users by submitting "/../" in the search bar, enabling user enumeration and reconnaissance.
impact: |
Unauthenticated attackers can explo
Nuclei
Titan FTP Server < 10.40 Move Function - Directory Traversal
nuclei·CVSS 5.0
CVE-2014-1841 [MEDIUM] Titan FTP Server < 10.40 Move Function - Directory Traversal
Titan FTP Server < 10.40 Move Function - Directory Traversal
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability in the Move function. Remote attackers can copy the complete home folder of another user by exploiting the ../ path traversal in the search-bar value, allowing unauthorized access to sensitive user data.
Template:
id: CVE-2014-1841
info:
name: Titan FTP Server < 10.40 Move Function - Directory Traversal
author: pussycat0x
severity: medium
description: |
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability in the Move function. Remote attackers can copy the complete home folder of another user by exploiting the ../ path traversal in the search-bar value, allowing unauthorized access to sens
Nuclei
Titan FTP Server < 10.40 - User Properties Traversal
nuclei·CVSS 5.0
CVE-2014-1843 [MEDIUM] Titan FTP Server < 10.40 - User Properties Traversal
Titan FTP Server < 10.40 - User Properties Traversal
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability that allows remote attackers to view "Properties" of user folders via path traversal. This enables user enumeration and access to sensitive user information that could aid in launching further attacks.
Template:
id: CVE-2014-1843
info:
name: Titan FTP Server < 10.40 - User Properties Traversal
author: pussycat0x
severity: medium
description: |
Titan FTP Server versions prior to 10.40 build 1829 contain a directory traversal vulnerability that allows remote attackers to view "Properties" of user folders via path traversal. This enables user enumeration and access to sensitive user information that could aid in launching further attacks.
imp
arXiv
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
arxiv_fulltext·2026-01-21
SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
[SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis]SAGA: Detecting Security Vulnerabilities Using Static Aspect Analysis
Yoann Marquer
[email protected]
0000-0002-4607-967X
Domenico Bianculli
[email protected]
0000-0002-4854-685X
Interdisciplinary Centre for Security, Reliability, and Trust (SnT), University of Luxembourg
Luxembourg
Lionel C. Briand
[email protected]
0000-0002-1393-1010
School of Electrical and Computer Engineering, University of Ottawa
Canada
Lero SFI Centre for Software Research, University of Limerick
Ireland
## Abstract
Python is one of the most popular programming languages; as such, projects written in Python involve an increasing number of diverse security vulnerabilities.
However, existing state-of-the-art analysis tools for
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
bugzilla·2014-09-22·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for python-requests: see blocks bug list
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
bugzilla·2013-12-26·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects m
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
bugzilla·2013-12-26·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for python-r
Bugzilla
CVE-2014-1829 python-requests: redirect can expose netrc password
bugzilla·2013-12-26·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 python-requests: redirect can expose netrc password
CVE-2014-1829 python-requests: redirect can expose netrc password
Python-requests was found to have a vulnerability, where the attacker can retrieve the passwords from ~/.netrc file through redirect requests, if the user has their passwords stored in the ~/.netrc file.
If site A redirects to site B, and user had a password for site A in their ~/.netrc, then requests would send authorization information both to site A and to site B.
References:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108
Discussion:
Created python-requests tracking bugs for this issue:
Affects: fedora-all [bug 1046627]
Affects: epel-6 [bug 1046628]
---
Created attachment 841867
Test Case to reproduce this bug.
Some test scripts are attached to reproduce the bug, when executed, gives a Base64 encoded str
http://advisories.mageia.org/MGASA-2014-0409.htmlhttp://www.debian.org/security/2015/dsa-3146http://www.mandriva.com/security/advisories?name=MDVSA-2015:133http://www.ubuntu.com/usn/USN-2382-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108https://github.com/kennethreitz/requests/issues/1885http://advisories.mageia.org/MGASA-2014-0409.htmlhttp://www.debian.org/security/2015/dsa-3146http://www.mandriva.com/security/advisories?name=MDVSA-2015:133http://www.ubuntu.com/usn/USN-2382-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108https://github.com/kennethreitz/requests/issues/1885
2014-10-15
Published