CVE-2014-1830
published 2014-10-15CVE-2014-1830: Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.04%
78.9th percentile
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | requests | < requests 2.3.0-1 (bookworm) | requests 2.3.0-1 (bookworm) |
| opensuse | opensuse | — | — |
| python | requests | <= 2.2.1 | — |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0-1 | 2.3.0-1 |
| python | requests | >= 0 < 2.3.0 | 2.3.0 |
| python | requests | >= 0 < 2.2.1-1ubuntu0.1 | 2.2.1-1ubuntu0.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Requests
osv·2022-05-14
CVE-2014-1830 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Requests
ghsa·2022-05-14
CVE-2014-1830 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Requests
Exposure of Sensitive Information to an Unauthorized Actor in Requests
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
OSV
CVE-2014-1830: Requests (aka python-requests) before 2
osv·2014-10-15·CVSS 5.0
CVE-2014-1830 [MEDIUM] CVE-2014-1830: Requests (aka python-requests) before 2
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
OSV
requests vulnerabilities
osv·2014-10-14·CVSS 5.0
CVE-2014-1829 [MEDIUM] requests vulnerabilities
requests vulnerabilities
Jakub Wilk discovered that Requests incorrectly reused authentication
credentials after being redirected. An attacker could possibly use this
issue to obtain authentication credentials intended for another site.
(CVE-2014-1829, CVE-2014-1830)
Ubuntu
Requests vulnerabilities
vendor_ubuntu·2014-10-14·CVSS 5.0
CVE-2014-1829 [MEDIUM] Requests vulnerabilities
Title: Requests vulnerabilities
Summary: Requests could be made to expose authentication credentials over the
network.
Jakub Wilk discovered that Requests incorrectly reused authentication
credentials after being redirected. An attacker could possibly use this
issue to obtain authentication credentials intended for another site.
(CVE-2014-1829, CVE-2014-1830)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2014-1830: requests - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sens...
vendor_debian·2014·CVSS 5.0
CVE-2014-1830 [MEDIUM] CVE-2014-1830: requests - Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sens...
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
Scope: local
bookworm: resolved (fixed in 2.3.0-1)
bullseye: resolved (fixed in 2.3.0-1)
forky: resolved (fixed in 2.3.0-1)
sid: resolved (fixed in 2.3.0-1)
trixie: resolved (fixed in 2.3.0-1)
Red Hat
python-requests: Proxy-Authorization header leak
vendor_redhat·2013-12-25·CVSS 5.0
CVE-2014-1830 [MEDIUM] python-requests: Proxy-Authorization header leak
python-requests: Proxy-Authorization header leak
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: python-requests (Red Hat Enterprise Linux 7) - Under investigation
Package: python-requests (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Under investigation
Package: python-requests (Red Hat OpenStack Platform 4) - Under investigation
Package: python-requests (Red
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
bugzilla·2014-09-22·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for python-requests: see blocks bug list
Bugzilla
CVE-2014-1830 python-requests: Proxy-Authorization header leak
bugzilla·2014-09-22·CVSS 5.0
CVE-2014-1830 [MEDIUM] CVE-2014-1830 python-requests: Proxy-Authorization header leak
CVE-2014-1830 python-requests: Proxy-Authorization header leak
It was discovered that the python-requests Proxy-Authorization header was never re-evaluated when a redirect occurs. The Proxy-Authorization header was sent to any new proxy or non-proxy destination as redirected.
References:
https://github.com/kennethreitz/requests/issues/1885#issuecomment-33793651
Discussion:
Upstream Issue:
https://github.com/kennethreitz/requests/issues/1885
Upstream Commit:
https://github.com/kennethreitz/requests/commit/4d8cb3244e8e4f84b250c10a48e025f9a8bf6137
---
Victims Record:
https://github.com/victims/victims-cve-db/blob/master/database/python/2014/1830.yaml
---
Created python-requests tracking bugs for this issue:
Affects: fedora-all [bug 1046627]
Affects: epel-7 [bug 1144910]
Affects:
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
bugzilla·2013-12-26·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects m
Bugzilla
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
bugzilla·2013-12-26·CVSS 5.0
CVE-2014-1829 [MEDIUM] CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
CVE-2014-1829 CVE-2014-1830 python-requests: various flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for python-r
http://advisories.mageia.org/MGASA-2014-0409.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00095.htmlhttp://www.debian.org/security/2015/dsa-3146http://www.mandriva.com/security/advisories?name=MDVSA-2015:133https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108https://github.com/kennethreitz/requests/issues/1885http://advisories.mageia.org/MGASA-2014-0409.htmlhttp://lists.opensuse.org/opensuse-updates/2016-01/msg00095.htmlhttp://www.debian.org/security/2015/dsa-3146http://www.mandriva.com/security/advisories?name=MDVSA-2015:133https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=733108https://github.com/kennethreitz/requests/issues/1885
2014-10-15
Published